Skip to content

What is two-factor authentication?

Two-factor authentication requires a second proof of identity in addition to your password, typically a time-based code from an app, a hardware security key, or a biometric check. A stolen password is no longer enough on its own, though phishable codes can still be relayed.

Topic
Authentication
Also called
2FA, multi-factor authentication, MFA
Reading time
1 min
Reviewed
On this page

The factors ranked by strength

Hardware security keys using FIDO2 are strongest, because they verify the site's identity and cannot be relayed by a phishing page. Authenticator apps generating TOTP codes are strong and universally available. SMS codes are the weakest common option, vulnerable to SIM swapping, but still far better than no second factor.

Where to enable it first

Your email account, before anything else. Email is the reset channel for every other account you own, which makes it the single highest-value target. Then financial accounts, then your password manager, then everything else.

Sources

These primary references support the terminology and current security guidance used in this definition.

Make one account easier today.

Start with the password you keep reusing or the bank card that still shares a PIN. MoolKey is free, and you do not need to move everything at once.

Free forever Works offline Phone or computer