PasswordCrunch.com
Account Security

What Is Two-Factor Authentication?

PasswordCrunch.com  ·  5 min read

Two-factor authentication (2FA) means proving your identity with two different types of evidence instead of one. A password alone is "something you know" — and anything you know can be phished, guessed or leaked in a breach. 2FA adds a second, different kind of proof, so a stolen password on its own is no longer enough to get in.

The three categories of "factor"

Genuine 2FA combines two of these categories. A password plus a security question isn't really two-factor — both are "something you know," and both can be looked up or guessed the same way.

Common methods, ranked by strength

  1. Hardware security keys (e.g. FIDO2/WebAuthn keys) — the strongest option. Phishing-resistant, because the key cryptographically verifies the actual website domain.
  2. Authenticator apps (generating time-based one-time codes) — strong, and not vulnerable to SIM-swapping the way SMS is.
  3. Push notifications from an app, approved with a tap — convenient, though vulnerable to "prompt bombing" if a user approves without checking.
  4. SMS codes — better than nothing, but vulnerable to SIM-swap attacks where an attacker convinces a carrier to port your number to their device.

Any of these is dramatically better than a password alone. The ranking matters most for high-value accounts like email and banking, where it's worth choosing the strongest option available.

Why it works against real attacks

2FA is specifically effective against credential stuffing and most password-reuse attacks, because the attacker can have a perfectly valid, correct password and still fail to log in without the second factor. It's one of the highest-leverage security changes an individual account holder can make, and it takes minutes to set up.

Where to turn it on first

Start with your email account — it's usually the recovery path into everything else you own — then your password manager, then banking, then anywhere else it's offered. Most major services support at least an authenticator app option under their account security settings.

Put this into practice right now.

Generate a strong password →