Security

Two-Factor Authentication

A form of multi-factor sign-in that uses two different factor types, such as a password and a security key. The exact protection varies by method; a code that can be relayed to a fake sign-in page is not phishing-resistant.

How it works

Two-factor authentication requires two different kinds of evidence to sign in, such as a password and possession of an approved authenticator. Two passwords are still the same kind of factor. The purpose is to make a stolen password insufficient on its own, while the strength depends on the method and recovery process.

A practical example

A service might ask for a password followed by a code from an authenticator app. Someone who has only the password would lack the second requirement. However, a false sign-in page can attempt to trick the user into providing both in real time, so the additional step does not make every method phishing-resistant.

What to check

Enable the method through the service’s genuine account settings and register a recovery option before relying on it. Confirm that the correct account appears in the authenticator and store any backup codes securely. Test sign-in while the current session remains available, and plan what happens if the phone or token is lost.

Limits and safe use

Never approve an unexpected sign-in prompt just to make it disappear or give a caller a verification code. Recovery weaknesses can undermine the setup. Two-factor authentication does not protect every already-open session or infected device, and changing phone numbers may require updating account recovery separately. Prefer stronger supported methods where practical.

Technical sources

← All glossary terms