Kasspar kasspar.com
LESSON 3 / of 6

Accounts & two-factor

What a second factor really protects against, which kinds are strongest, and why email comes first.

Accounts & two-factor sign-in

Two-factor authentication (2FA, also called multi-factor or MFA) means a password alone is not enough to sign in. You also need something you have: a code from an app, a prompt on your phone, or a small hardware key. If a criminal steals or guesses your password, they still cannot get in without that second thing.

Not all second factors are equal. Codes sent by text message are far better than nothing, but a determined attacker can hijack a phone number ("SIM swapping") or trick you into reading the code out. Authenticator apps are better. Passkeys and hardware security keys are best, because they only work on the genuine website, which makes them effectively phishing-proof.

Your email account deserves the strongest protection you have, because the "forgot password" link on almost every other service lands there. Whoever controls your email can eventually control everything else.

Common myth"Nobody would bother targeting me." Most account takeovers are automated and indiscriminate. Attackers do not choose you; their software tries everyone and keeps whatever opens.
Do these
  1. Turn on 2FA for email, then bankingLook in the account's security settings. Prefer an authenticator app or a passkey over text-message codes where offered.
  2. Save your backup codesEvery service gives you a set when you enable 2FA. Store them in your password manager or on paper in a safe place.
  3. Never share a code with anyone who asksA code arriving when you did not request it means someone has your password. Change it. No legitimate company will ever phone you for a code.