What is 2-Factor Authentication?

2-Factor Authentication (2FA) has emerged as probably the single most important security tool you can enable to protect yourself online. A growing number of apps and services offer 2FA to their users, but most people either don't know what it is, or perceive it as an added hassle and opt not to take advantage of the feature.

Definition

Multi-factor authentication (MFA) is a method of computer access control in which a user is only granted access after successfully presenting several separate pieces of evidence to an authentication mechanism — typically at least two of the following categories: knowledge (something they know); possession (something they have), and inherence (something they are).

Authentication Types

Knowledge: Password, PIN, secret answer to a security question, pattern lock, etc. Possession: Magnetic swipe card, RFID chip, key, or other physical object. Inherence: Biometrics such as fingerprint, voice-print, iris, etc.

How It Works

Most commonly for consumer apps and services, 2FA involves adding an additional step to the typical username/password form. When the app or service detects that a user is attempting to log in from an unrecognized device, it will force the user to enter the second authentication factor, typically a code either sent via SMS text message to the owner's phone, or created via an app on their smartphone. The second factor is only requested when logging in from a new device or following an update from the service. This means that you aren't hassled with this process during each login. However it is enough to protect you from an attacker attempting to access your account from the other side of the world. Even if they steal or guess your password, they will not be able to enter the account unless they also have access to your phone.

Apps and Services

Below are a few key points to keep in mind regarding online security:
  • Protect Your Identity: 2FA should be used for any service that offers it, but start by protecting your bank accounts, email, and social media. I suggest prioritizing services which, if compromised, would enable someone to steal your identity. Think critically about where you have the most to lose, and then reinforce your security.
  • Preserve Your Reputation: It is important to protect your personal and company social media accounts with 2FA because they not only have a ton of personal information, but also the ability to broadcast messages to the entire world. If your account is hacked, the attacker can cause irreparable harm to your brand by publishing content which will appear to be coming from you.
  • Get Help: Use twofactorauth.org. I highly recommend browsing through their database and enabling 2FA on any service you use which offers it.

Apple

If you have any iOS device (iPhone, iPad, etc.) or Mac, your data is being backed up to iCloud. Securing that data is critical.
  1. Sign in to your Apple ID account page.
  2. Under Two-Step Verification, click Get Started.
  3. Answer your security questions and follow the steps to finish your set up.

Facebook

2FA for Facebook can be found in their settings for "Login Approvals". To turn on login approvals, go to your Security Settings, click the Login Approvals section, check the box and click Save Changes. Note that you need a mobile phone number listed on your account. See Facebook's help documentation for full details.

Google

Your Google account covers all of their services, including Gmail, Google Drive/Docs, and YouTube. Enable Google 2-Step Verification to protect everything connected to your account.

Microsoft

To turn two-step verification on or off: go to the Security settings page, sign in with your Microsoft account, and under Two-step verification choose Set up two-step verification. See Microsoft Support for full instructions.

Twitter

Twitter's Help Center Article: Using login verification

Links to Help for Other Popular Services