What is two-factor authentication?
Two-factor authentication requires a second proof of identity in addition to your password, typically a time-based code from an app, a hardware security key, or a biometric check. A stolen password is no longer enough on its own, though phishable codes can still be relayed.
- Topic
- Authentication
- Also called
- 2FA, multi-factor authentication, MFA
- Reading time
- 1 min
- Reviewed
On this page
The factors ranked by strength
Hardware security keys using FIDO2 are strongest, because they verify the site's identity and cannot be relayed by a phishing page. Authenticator apps generating TOTP codes are strong and universally available. SMS codes are the weakest common option, vulnerable to SIM swapping, but still far better than no second factor.
Where to enable it first
Your email account, before anything else. Email is the reset channel for every other account you own, which makes it the single highest-value target. Then financial accounts, then your password manager, then everything else.
Sources
These primary references support the terminology and current security guidance used in this definition.
