Security

2FA / MFA

Two-factor and multi-factor authentication add independent evidence to account sign-in. Protection depends on the method and the security of recovery options.

Laptop sign-in protected by a phone and a separate security key.

What it means

Factors describe what you know, have or are. Two passwords are still one factor type. An authenticator code, security key or suitably protected passkey can provide additional evidence. Codes and push approvals can be tricked or relayed; availability of phishing-resistant methods depends on the service.

How this affects everyday use

Account takeover often begins with reused passwords, a convincing false sign-in page or an unexpected approval request. Lost phones can also leave legitimate users unable to sign in.

A practical example

An email password leaks from another website. A separate security key can prevent that password alone from opening the mailbox, provided the recovery route is also protected.

What to check

  • Check which verification methods the account actually accepts.
  • Review backup codes, recovery contacts and registered devices.
  • Inspect recent sign-ins and prompts you did not initiate.

Practical next steps

  • Register a stronger supported method from the genuine account settings.
  • Store recovery codes separately from the everyday sign-in device.
  • Reject unexpected prompts and revoke unknown devices or sessions.

Keeping it reliable

Plan recovery before replacing a phone. Use unique passwords, keep spare verification methods secure and periodically review them. MFA reduces particular risks; it does not make an infected or unlocked device safe.

Technical sources

← All glossary terms