openideurope.eu

Two-factor authentication (2FA) explained: types and setup

What two-factor authentication is, how SMS, apps, push and security keys differ, which to choose and how to switch it on without locking yourself out.

Login securityPublished

Two-factor authentication, usually shortened to 2FA, means you prove who you are with two different things instead of just a password. Even if a criminal gets your password through a data breach or a fake login page, they still need the second factor to get in. The German Federal Office for Information Security (BSI) advises using it wherever it is offered.

The three kinds of factor

  • Something you know: a password or PIN.
  • Something you have: your phone, an authenticator app on it, or a security key.
  • Something you are: a fingerprint or face.

Real two-factor protection combines two different kinds. Two passwords, or a password and a security question, are not two factors, because both are things you know.

The main 2FA methods compared

Method How it works Strengths Weaknesses
SMS code A code arrives by text message Works on any phone, no app Can be intercepted or redirected, see SMS codes and their risks
Email code A code arrives by email Easy Only as safe as the email account
Authenticator app (TOTP) An app shows a six-digit code that changes every 30 seconds Works offline, no phone number involved Code can still be typed into a fake site, see how TOTP codes work
Push approval You tap Approve on a prompt Quick Prone to approval by mistake, and a poor fit where phishing is a threat
Hardware security key You plug in or tap a physical key Strongest, phishing-resistant Costs money, you need a spare, see hardware security keys
Passkey Your device proves it holds a private key Strong and easy, phishing-resistant Not supported everywhere yet, see passkeys explained
Backup codes Printed single-use codes A safety net Must be stored securely, see backup codes

The BSI notes that authenticator apps and hardware-based methods are stronger than codes sent by text message, and that hardware-based methods offer a particularly high level of security. It also advises against receiving a text message code on the same device you use to log in, since the factors are then not properly separated.

Which accounts first

Start where a break-in would hurt most:

  1. Your main email account. It can reset the passwords of almost everything else.
  2. Apple, Google or Microsoft account. These hold your devices, files, photos and often your passkeys.
  3. Banking, payment and shopping accounts. Banks in the EU already require strong customer authentication for payments, but your own login still deserves a strong factor.
  4. Your password manager. It is the key to everything, so secure it with the strongest factor on offer.
  5. Social media and messaging. Takeovers here are used to scam your contacts.

How to switch on 2FA

  1. Open the account’s security or privacy settings and look for “Two-step verification”, “Two-factor authentication” or “Login verification”.
  2. Choose the method. If an authenticator app or security key is available, prefer it over SMS.
  3. For an authenticator app, scan the QR code with the app and enter the first code to confirm. Our comparison of authenticator apps can help you choose one.
  4. Save the backup codes the service shows you. Store them offline, for example in a password manager or printed in a safe place.
  5. Test it by logging out and in again.

What it looks like in practice

You enter your username and password as usual. The service then asks for a second proof: a six-digit code from your app, a tap on a key, or a confirmation on your phone. Many services let you tick “trust this device” so you are not asked every time on your own computer, which keeps the extra step to a few seconds a day. If you use a passkey, the two steps merge into one: you unlock the passkey with your fingerprint or face, and that already counts as both factors.

If you pay online in the EU, you will already know a version of this. Rules for card and bank payments require strong customer authentication, which is why your bank asks you to confirm a payment in its app or with a code. Your own account logins deserve the same care.

Avoid the common mistakes

  • Using one phone for everything with no backup. Add a second method or a second device.
  • Ignoring recovery. If your only second factor is lost and you have no codes, recovery can take days. Read about account recovery in advance.
  • Approving prompts you did not start. If an approval request appears out of the blue, deny it and change your password.
  • Entering codes on a page you reached through a link in a message. Type the address yourself or use a bookmark.

The next step up

Standard 2FA already blocks most automated attacks. If you want protection against the clever ones, where a fake site relays your password and code in real time, move to phishing-resistant MFA: passkeys and hardware security keys. You do not need to be an expert, and you do not need to do it everywhere at once. One strong second factor on the three or four accounts that matter is a very good start.

Frequently asked questions

What is the difference between 2FA and MFA?

Two-factor authentication uses exactly two proofs, such as a password plus a code. Multi-factor authentication (MFA) is the broader term for two or more. In everyday use the words are often interchangeable.

Which 2FA method should I choose?

Use the strongest one the service offers and you can manage reliably. In order: a passkey or hardware security key, then an authenticator app, then push approval, then SMS. Any second factor is better than none.

Does 2FA make me completely safe?

No, but it blocks the most common attack, which is a stolen or reused password. Weaker second factors, such as SMS or one-time codes you type into a fake site, can still be tricked. Phishing-resistant methods close that gap.

What if I lose my phone with the authenticator app?

That is what backup codes and a second registered method are for. Keep the codes offline, and consider an authenticator app that offers encrypted backup or a hardware key as a second device.

Is 2FA worth it for small accounts?

Prioritise by damage. Your email account unlocks password resets for everything else, so it comes first, followed by money, cloud storage and social accounts. Low-value accounts can wait.

More in Login security