Two-Factor Authentication 2FA

A sign-in that needs two different kinds of proof — usually something you know and something you hold — so a stolen password is not enough on its own.

Also known as 2FA MFA multi-factor authentication

Definition

The first factor is your password. The second is a code from an app, a hardware key, or a message to a device you own.

It is the single highest-value change most accounts can make: it defeats every attack that ends with "and then they had the password".

Questions about Two-Factor Authentication

Is an SMS code good enough?
It is far better than nothing, but an authenticator app or a hardware key is stronger — an SMS can be intercepted or redirected by taking over the phone number.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.