Two-Factor Authentication, Explained

Two-Factor Authentication, Explained

The single best thing you can do to protect your accounts, and which type to choose.

Two-factor authentication (2FA) adds a second step when you log in, usually a code or an approval on your phone. Even if someone steals your password, they can't get in without that second step.

The types, from good to best

  • Text message codes: much better than nothing, though codes can be intercepted in SIM-swap scams.
  • Authenticator apps: apps that generate a new code every 30 seconds. Stronger than text messages.
  • Passkeys and security keys: the strongest option, and very resistant to phishing.

Where to turn it on first

  • Your email account.
  • Banking and investment accounts.
  • Your phone carrier account.
  • Social media and cloud storage.

Don't lock yourself out

When you set up 2FA, save the backup codes somewhere safe, like a password manager or a printed copy at home.

Never share a code

No real company will call or text asking you to read back a login code. If someone does, it's a scam.

Setting it up

Look for "security" or "sign-in" settings on each account. Ask a family member or local library for help if needed.

Keep your phone number up to date

If you change phones or numbers, update your accounts right away so you don't get locked out.

Beware of code requests

Scammers sometimes call pretending to be your bank and ask for a code. Never share it.