Progress: Module 2 of 2
๐ Two-Factor Authentication
Two-factor authentication (2FA) adds a second layer of security beyond your password. Even if someone steals your password, they still can't access your account without the second factor.
What is Two-Factor Authentication?
2FA requires two different types of verification:
- Something you know - Your password or PIN
- Something you have - Your phone, security key, or authentication app
- Something you are - Your fingerprint, face, or biometric data
True 2FA requires factors from two different categories.
Types of Two-Factor Authentication
1. SMS Text Messages
โ Easy to set up, works on any phone
โ Vulnerable to SIM swapping, requires cell service
2. Authentication Apps
โ More secure than SMS, works offline, free
โ Requires smartphone, codes expire quickly
Examples: Google Authenticator, Microsoft Authenticator, Authy
3. Hardware Security Keys
โ Most secure option, resistant to phishing
โ Costs money ($25-50), can be lost
Examples: YubiKey, Google Titan
4. Push Notifications
โ User-friendly, shows login location
โ Vulnerable to "MFA fatigue" attacks
5. Biometric Authentication
โ Convenient, can't be forgotten
โ Requires compatible hardware, can't be changed if compromised
Which Accounts Need 2FA?
Enable 2FA on these accounts first:
- Email - Key to resetting other passwords
- Financial - Banks, credit cards, PayPal
- Social media - Facebook, Instagram, Twitter/X
- Cloud storage - Google Drive, Dropbox, iCloud
- Password managers - Protect your vault
Common Mistakes to Avoid
- Approving without thinking - Always verify login details before approving push notifications
- Using only SMS - Use authenticator apps or hardware keys when possible
- Not saving backup codes - Store them securely in case you lose your device
- Sharing 2FA codes - Never share codes with anyoneโit's always a scam
How to Enable 2FA
- Go to account security settings
- Find the 2FA/MFA option (may be called "Two-Step Verification")
- Choose your method (authenticator app recommended)
- Follow setup instructions
- Save backup codes in a secure location
- Test it by logging out and back in
Test Your Knowledge
๐ Module 2 Quiz
Answer these 5 questions to test your understanding. You need 4 correct to pass.