Security

Why You Should Turn On Two-Factor Authentication Today

Passwords leak. They get reused, guessed, and phished. Two-factor authentication is the single control that keeps a stolen password from being enough on its own.

What 2FA actually does

Two-factor authentication (2FA) adds a second, short-lived proof of identity on top of your password — usually a one-time code sent by SMS or email, or generated by an authenticator app. Even if someone learns your password through a data breach, a phishing page, or simple guesswork, they still can't sign in without that second code, which only reaches your own device.

The common types of 2FA

  • SMS or email OTP. A short numeric code sent to your registered mobile number or email each time you sign in from a new device. Convenient, and far better than no second factor at all.
  • Authenticator apps. Apps that generate a rotating code on your phone without needing a network connection, which makes them harder to intercept than SMS.
  • Push approval. A notification you simply tap to approve or deny — some platforms offer this as an alternative to typing a code.

How to turn it on

  1. Open your account's security or settings menu on the official website or app.
  2. Look for "Two-Factor Authentication," "2FA," or "Verification Settings."
  3. Choose your preferred method and confirm it with your registered mobile number or an authenticator app.
  4. Save any backup codes provided somewhere safe and offline — they're your fallback if you lose access to your primary method.

Mistakes that quietly defeat 2FA

2FA only works if the second factor stays private. The most common way people undermine it is by sharing a one-time code with someone claiming to be "support" — no legitimate support agent ever needs your OTP. The second most common mistake is turning 2FA off after it feels like friction; a few extra seconds at login is a small price for making stolen passwords far less useful to an attacker.

For more on spotting attempts to trick you out of a code, see our guide on recognizing fake login pages.