Two-factor authentication (2FA)
A second login step beyond your password, so a stolen password isn't enough.
Also known as: 2FA, multi-factor authentication, MFA
Updated June 2026
Two-factor authentication (2FA) requires a second proof of identity in addition to your password — something you have (a phone, a security key) or are (a fingerprint).
Strongest to weakest
- Hardware security keys (FIDO2/passkeys) — phishing-resistant.
- Authenticator apps (TOTP codes) — solid and free.
- SMS codes — better than nothing, but vulnerable to SIM-swap attacks.
The takeaway
Turn 2FA on for email, banking and brokerage first — those are the accounts that protect everything else. Prefer an app or key over SMS where you can.