Just out todayClimate & energy tech: We ran the Ibadan solar forecast ourselves. Every number came back.AI agents & MCP: What a 49.1% attack rate does not tell youCybersecurity: The MCP scanner number that should worry you

Explainer/Cybersecurity

What is two-factor authentication?

Two-factor authentication asks for a second proof after your password, so a stolen password is no longer enough. Learn the methods ranked from weakest to strongest, and how to avoid being locked out.

The short answer

Two-factor authentication means proving who you are with two different kinds of proof before an account opens. The first is usually a password, which is something you know. The second is something you have, such as a phone or a security key, or something you are, such as a fingerprint. A stolen password alone then gets nobody in.

Grade 5 reading level5 min read

You stand at a cash machine. You put in your card, and then you type your PIN. Two different things are needed, and one alone is worthless. A thief with your card and no PIN gets nothing, and a thief with your PIN and no card gets nothing either.

That is two-factor sign-in, and you have used it for years without calling it that.

Online accounts were built the other way round, and for a long time one password was the whole lock. However, passwords get guessed, reused and stolen in their millions. Therefore the answer was to add a second, different proof.

What two-factor authentication means

Two-factor authentication means proving who you are with two proofs of different types. It is often shortened to 2FA, and many services call it two-step verification, which is the same idea.

Note the word “different”, and two passwords are not two factors. Neither is a password plus a security question, because both are things you remember. A thief who learns one can often learn the other.

The point of 2FA is simple, and a stolen password on its own stops being enough.

The three kinds of proof

Every check falls into one of three groups.

  • Something you know. A password, a PIN, an answer.
  • Something you have. A phone, a bank card, a small key that plugs in.
  • Something you are. A fingerprint, a face, a voice.

Real 2FA takes one proof from two of these groups. The cash machine takes something you have and something you know, and your phone takes something you have and something you are.

The methods, from weakest to strongest

Not every second step is equal, so here they are in order.

Codes by SMS. A text arrives with six digits, and it is common and easy. It is also the weakest, because a criminal can talk a shop into moving your number to a new SIM card. That is called a SIM swap, and then your codes go to them.

Codes from an app. An app on your phone makes a fresh code, usually every thirty seconds. No network is needed, so no SIM swap can touch it. It is a clear step up and it is free.

Push approval. Your phone asks “was this you?” and you tap yes. It is quick. However, attackers send a flood of requests late at night hoping you tap yes to make it stop. Good versions now show a number you must match.

A security key. A small device on your key ring, used by touch or by tapping it on the phone. It checks the web address of the site before it answers.

A passkey. The same maths as a security key, held on your phone or laptop and released by your face or fingerprint. There is no code to type and no password to steal.

The last two share one quality that matters more than any other. THEY CANNOT BE PHISHED. A fake page has the wrong address, so the key stays silent. Learn why that matters in our guide to phishing.

What it stops, and what it does not

It stops the most common attack there is. Somebody buys a list of stolen passwords and tries them across many sites. Therefore, with a second step, your password alone opens nothing.

What does it not stop? Several things.

  • Bad software already on your phone or laptop.
  • A fake page that takes your code and passes it to the real site while you wait.
  • A thief who steals the session after you have signed in.
  • You, if you read the code aloud to a caller who says they are from the bank.

That last point deserves a rule of its own. No real bank, network or employer will ever ask for your one-time code, and anyone who does is stealing from you.

Where you already meet it

Mobile money is a good example. You need the phone in your hand and the PIN in your head. Bank apps do the same with a fingerprint and a device check.

Work systems now ask for a second step before opening email from a new place. That is a normal part of zero trust security, where no login is trusted just because it looks familiar.

Even your front door may use it, and a gate with a code and a card is the same design in metal.

What to do when you lose your phone

This is the fear that stops people turning 2FA on. It is a fair fear, and it has a plain answer. Set up your escape route on the day you set up the lock.

  1. Save the recovery codes the service gives you, and print them or write them down, and keep them where you keep your passport.
  2. Add a second method, such as a spare key or a second phone.
  3. Use an app that can restore your codes to a new phone.
  4. Keep a current email address on the account, because that is how you get back in.

Do this once for your email account first. Your email resets everything else, so it is the account that protects all the others.

Common mistakes

The first mistake is turning it on for the bank and stopping there. Attackers go for your email, because from there they reset the bank.

The second is approving a request you did not start, so treat an unexpected prompt as an alarm. Say no, then change that password at once.

The third is keeping SMS as your only method when the service offers better. Move to an app or a key, and keep SMS as a backup only if you must.

The fourth is ignoring it at work, and one account without a second step can be the way ransomware reaches everybody else.

Turn it on today, in this order

Give this twenty minutes. Open your email account settings and find the security page. Turn on a second step, and pick an app or a passkey rather than SMS. Save the recovery codes.

Then repeat it for your mobile money and bank, your work account, and any account that holds a card number. After that, check the list of devices signed in to your email and remove the ones you do not recognise.

Just Out Tech explains new research in plain language. This article was drafted with AI assistance and checked by a human against the original source.

What to remember
  • Two-factor authentication only works when the two proofs come from different groups, so a password plus a security question does not count.
  • Passkeys and hardware security keys are the strongest second step because they check the web address, which makes a copied sign-in page useless.
  • Anyone turning on two-factor authentication should save the recovery codes at the same time, because that is the way back in when a phone is lost.

Questions people ask

Is SMS two-factor authentication safe enough?

It is far better than a password alone, and it blocks the most common bulk attacks. It is also the weakest of the methods, because a criminal can move your number to a new SIM card and receive your codes. Use an app or a passkey where the service offers one, and keep SMS as a backup.

What is the difference between 2FA and a passkey?

2FA adds a second proof on top of a password. A passkey replaces the password altogether with a secret held on your device and released by your face, fingerprint or PIN. A passkey also checks the address of the site, so a fake page cannot use it.

What happens if I lose the phone with my codes on it?

You use the recovery codes the service gave you when you set it up, or a second method such as a spare key or another phone. This is why the codes should be saved somewhere safe on day one. Without them, getting back in can take days of identity checks.

Can attackers get past two-factor authentication?

Yes, in some cases. A fake sign-in page can collect your code and pass it to the real site in real time. Bad software on your device can steal the session after you sign in. A hardware key or a passkey defeats the fake page attack, because it refuses to answer the wrong address.

About the author

Mark Alex

Mark Alex is the founder and Managing Director of Real Biz Digital, a technology company operating out of Nairobi since 2018. He works in agentic AI and the Model Context Protocol, AI governance, enterprise software architecture and cybersecurity. He holds an MSc in Mechatronical Engineering from Obuda University in Budapest and a BSc in IT, Forensic Technology and Cybercrime, from USIU-Africa in Nairobi, and has published IEEE conference research on an AI-powered digital twin for greenhouse systems. He is the author of seven books. Between 2020 and 2024 he mentored more than 200 university students and interns in Nairobi. He writes every Just Out Tech article from the original research paper.