Most of the protected information we access online — and often offline too — is secured by… a login and a password. Those two pieces of information are the fundamental basis of security for a lot of valuable data. Valuable, even if some people think it's worth nothing. I won't scare you with numbers on how many accounts get hijacked every day, how many people end up with fake messages from “family and friends” as a result, or how huge the resulting scams can be — even if you only have a handful of friends on Facebook. Login and password. Underrated, neglected, and often shared left and right, unprotected, unsecured. Okay, a sip of strong coffee, and let's get to it.
Two-factor authentication (2FA) requires entering two pieces of information to verify your identity before you get access to an account. Let me be clear right away: a login and password together count as one piece of information, one factor, one level. When we talk about two factors, two levels, two-step authentication, or multi-level authentication, we're usually talking about entering a password plus a one-time 2FA code.
Login and password plus extra authentication — 2FA and MFA
2FA stands for Two-Factor Authentication. MFA stands for Multi-Factor Authentication.
Once you turn on 2FA, even if there's a security breach or a hacker compromises your password, your account will still be safe. Two-step authentication is designed to require two elements that identify the user or authorize the action.
Sounds safe? On the surface, yes — if you dig into Google, you'll find that even this method can occasionally backfire. But let's assume that if you choose this kind of verification, you'll follow the recommendations of whoever built it, or the support suggestions from, say, Facebook, Google, Instagram, and so on.
But even Donald Trump needs two-step or even multi-step authentication to launch a nuclear warhead — starting with the red phone, an SMS code, a yellow sticky note on the monitor, two keys plus a third one hidden in his wife's handbag, and ending with his hamster's fingerprint. That's a joke, of course, but it's basically what multi-step authentication looks like. Sounds far too complicated, though. Doesn't it?
Two-factor authentication (2FA) or multi-factor authentication (MFA) adds an extra layer of security for your business — it helps close the security gaps in a standard approach based on a password alone. In today's online environment, basic security based on a username and password is easy prey for cybercriminals. Many logins can be cracked within minutes, and private data (such as personal and financial information) is increasingly at risk.
To really capture what two-factor and multi-factor authentication are about, it helps to look at the stages of identification and authorization through the lens of three questions. The answers to them also answer another question: what can serve as the second authentication factor — what, besides a login and password, can additionally protect us from unauthorized access?
- something the user knows (e.g. a password, PIN code, or answer to a secret question)
- something the user has (e.g. a token, mobile phone, USB key, key fob)
- something the user is (e.g. face or voice recognition, behavioral biometrics, a fingerprint, or a retina or iris scan)
How does two-factor authentication work?
When you log into an account, you'll be asked to authenticate using a username and password. That's the first step. You know these details, you use them every day, or — worse still — you've saved them in your browser or stuck them on a note on your monitor (I don't know which is worse).
You log in and… an SMS arrives. Sent to a specific phone number, containing a specific code you have to enter. Or you pull a token out of your pocket, click it, generate a key, and type it in. Or you put your finger on a fingerprint reader.
It's exactly this extra step in the authentication process that's designed to boost your security.
Where can I use two-factor authentication?
You should use two-factor authentication for every website, service, and app that supports it.
- Online banking (even on your phone, you still need to unlock the device and authorize payments with a PIN code or fingerprint, depending on your settings).
- Online shopping (Amazon, PayPal, Google Play, Allegro)
- Email (Gmail, Yahoo, Outlook — when logging into your mailbox or changing your account settings)
- Cloud storage accounts (Dropbox, Box, Google Drive, where sensitive data may be accessible)
- Social media accounts (Facebook, Instagram, LinkedIn, Tumblr, Twitter — often forgotten, underrated, but a powerful tool for scams and impersonation)
- Password managers (a password manager is usually protected by a single strong password, and the password file itself is encrypted). So the entire strength of that protection rests on a single password,
-
Messaging apps.
