Passwords get leaked far more often than most people realize — through data breaches, phishing pages, or simply being reused across too many sites. Two-factor authentication, often shortened to 2FA, adds a second checkpoint that makes a stolen password alone much less useful to an attacker.
How it actually works
After entering a correct password, 2FA asks for a second piece of proof: a code sent by text, a code generated by an authenticator app, or a physical security key. Even if someone has your password, they're stopped at this second step unless they also have access to your phone or key.
Not all 2FA methods are equal
- SMS codes: convenient but vulnerable to SIM-swap attacks in rare cases
- Authenticator apps: more secure, since codes are generated on the device itself
- Physical security keys: among the strongest options, since they require the actual device to be present
- Push notifications: quick to approve, but can be misused if you're not careful about approving unfamiliar requests
The strongest password in the world can still be stolen. A second factor is what turns a stolen password into a dead end.
Where to start
Enabling 2FA on email, banking, and any account tied to financial or personal information gives the biggest security return for the least effort. Most major platforms now offer it as a free setting buried a few taps into account security settings — worth the two minutes it takes to turn on.