Skip to content
Last updated: July 13, 2026
🕑 4 min read

Passwords get stolen every day. Data breaches, phishing emails, malware that logs keystrokes: there are dozens of ways a password can leak, and most of them are not your fault. Two-factor authentication (2FA) is the single cheapest, fastest upgrade you can make to your online security, because it means a stolen password alone is no longer enough to get into your account.

What two-factor authentication actually is

🔧 Free tool: Backup Plan Generator — Four questions, one personal 3-2-1 backup plan.

Logging in normally requires one thing: something you know (your password). Two-factor authentication adds a second, independent check: something you have (your phone or a hardware key) or something you are (a fingerprint or your face). An attacker on the other side of the world may steal what you know, but they usually cannot steal what you physically hold.

In practice, after you type your password, the service asks for a short code or a tap of approval that only your device can produce. That extra step takes you five seconds. For an attacker, it is often a full stop.

The main types of 2FA, from weakest to strongest

1. SMS text codes: better than nothing

The service texts you a six-digit code. This blocks casual attacks, but it has a well-known weakness: SIM swapping. A determined attacker convinces your mobile carrier to move your number to their SIM card, and from that moment your codes go to them. SMS codes can also be phished in real time by fake login pages. Use SMS only when a service offers nothing better.

2. Authenticator apps: the sweet spot for most people

Apps like Google Authenticator, Microsoft Authenticator, Aegis or 2FAS generate a fresh six-digit code on your phone every 30 seconds. The codes are created on the device itself, so there is nothing for a SIM swapper to intercept. Setup takes about a minute per account: scan a QR code, type the six digits once to confirm, done.

3. Passkeys and hardware keys: the gold standard

Passkeys, now supported by Google, Apple, Microsoft and a growing list of major sites, replace codes entirely with cryptographic keys stored on your device and unlocked with your fingerprint, face or PIN. Physical security keys such as a YubiKey work similarly but live on a small USB stick. Both are effectively phishing-proof: a fake login page cannot trick them, because the key checks the real website address before it responds.

Which accounts to protect first

Do not try to enable 2FA on fifty accounts in one evening. Prioritise the accounts that unlock everything else. Your email account comes first, because password resets for every other service land there; whoever controls your inbox eventually controls everything. After that, secure your password manager, your banking and payment apps, your Apple or Google account, and your main social media profiles, which are prime targets for impersonation scams.

How to set it up, step by step

  1. Install an authenticator app on your phone (2FAS and Aegis are free and privacy-friendly; Google and Microsoft Authenticator are fine too).
  2. Open the account you want to protect and find the security settings. Look for “Two-factor authentication”, “Two-step verification” or “Login approvals”.
  3. Choose “Authenticator app” when offered, then scan the QR code shown on screen with your app.
  4. Type the six-digit code from the app back into the website to confirm the link.
  5. Save the backup codes the site gives you. Print them or store them in your password manager – not in a screenshot on the same phone.

The mistake almost everyone makes: no backup plan

The most common 2FA disaster is not hacking – it is locking yourself out. Phones get lost, broken and stolen. Before you rely on an authenticator app, make sure you have at least one recovery route: the one-time backup codes every service offers during setup, a second device with the same authenticator, or a hardware key kept in a drawer. Two minutes of preparation saves you a week of painful account-recovery forms.

Common questions

Does 2FA slow me down every single login? No. Most services only ask for the second factor on new devices or after long gaps, so day-to-day you will barely notice it.

What if I change phones? Most authenticator apps now offer encrypted transfers or cloud backup. Move your codes before wiping the old phone, and keep those paper backup codes as a safety net.

Is 2FA unbeatable? Nothing is. Real-time phishing kits can still capture app codes if you type them into a fake site, which is why passkeys and hardware keys are the long-term direction. But even basic 2FA blocks the overwhelming majority of automated account-takeover attempts, which is exactly what most people need.

Enable it on your email today. It is the highest-value five minutes in personal security.

Keep reading

Computer Multiverse app

Get the Computer Multiverse app

Password & scam checkers, plain-English security help — straight from your home screen. No app store needed.