Two-factor authentication, often shortened to 2FA, adds a second step to the login process on top of your password. Instead of relying on something you know alone, it also asks for something you have or something unique to you, such as a code from an app on your phone, a text message, or a fingerprint. The idea is straightforward: even if someone gets hold of your password, they still can't get in without that second piece.
Why passwords alone aren't enough
Passwords get leaked in data breaches, reused across multiple sites, or guessed through automated attacks far more often than most people realise. Once a password is exposed, any account using that same password becomes vulnerable, sometimes without the account holder even knowing it happened. Two-factor authentication is designed to close that gap by requiring an additional, harder-to-copy element.
Common types of second factors
Authenticator apps generate a temporary code that refreshes every so often, and are generally considered more secure than codes sent by text message, since text messages can sometimes be intercepted. Hardware security keys offer another layer of protection for accounts that support them. Biometric options like fingerprints or facial recognition are also increasingly common, particularly on mobile devices.
- Adds a second, independent step beyond your password
- Protects accounts even if a password is stolen or guessed
- Authenticator apps and hardware keys are generally stronger than text-message codes
- Worth enabling on any account holding financial or personal information
The bottom line
Turning on two-factor authentication is one of the simplest, most effective steps available for protecting online accounts, particularly banking, email and crypto platforms. No security measure eliminates risk entirely, but this one meaningfully raises the bar for anyone trying to get in without permission.



