Two-step login: a stolen password isn't enough
Add a second step so that a leaked or phished password alone can't open your account. Learn which methods are strongest, how passkeys work, and how to lock your messengers.
TWO DIFFERENT THINGS
Something you know, plus something you have
A password is something you know. Two-step login (also called 2FA or two-factor authentication) adds something you have, usually your phone, or something you are, like your fingerprint. An attacker far away can steal what you know, but it's much harder for them to also hold your phone.
You type your email password, then the site asks for a 6-digit code from your phone. Someone with only your password gets stuck at that second screen.
Second steps, strongest first
- 1 · Passkey or security key
Works only on the real website, so it can't be phished. Unlocked with your fingerprint, face or phone PIN.
- 2 · Authenticator app
An app on your phone shows a new code every 30 seconds or so. Strong, though a very convincing fake page can still ask you for the code.
- 3 · Code by SMS
Better than nothing by a wide margin, but it depends on your phone number, which can be hijacked.
- 4 · Password only
One leak or one fake page and the account is gone.
Check yourself
Farhad's email password leaked in a breach, but he has two-step login with an authenticator app. An attacker tries the password. What happens, and what should Farhad do?
- The attacker gets in, because two-step only matters on new phones
- Nothing happens and Farhad doesn't need to change anything
- The attacker is stuck at the code step; Farhad should still change the password
- The app sends the code to the attacker as well, since he already has the correct password
Show the answer
The attacker is stuck at the code step; Farhad should still change the password
Right. The code lives only on Farhad's phone, so the password alone isn't enough. But one lock is now broken, so he should replace the password before anything else goes wrong.
THE APP
How an authenticator app works
When you turn it on, the website shows a QR code. You scan it with an authenticator app, and from then on the app and the site share a secret. Every 30 seconds or so, both use that secret and the current time to make the same short code. The app works even with no internet or SIM card, and the code never travels by SMS.
Logging in on a new laptop, you open the app, read 482 913 before it changes, and type it in. Ten seconds later a new code appears and the old one is useless.
THE WEAK SPOT
Why SMS codes are the weakest second step
An SMS code goes to your phone number, not your phone. In a SIM swap, an attacker convinces or bribes someone at a mobile operator to move your number to a new SIM, and your codes start arriving on their phone. SMS codes are also easy to talk people into reading out. Use SMS if it's the only option offered; switch to an app or passkey where you can.
Your phone suddenly shows no signal for hours, and then you get "password changed" emails. That pattern can mean your number was moved. Call your operator right away.
Check yourself
Match each second step to its weak spot or role
Show the answer
- Code by SMS → Can be redirected if your number is moved to another SIM
- Authenticator app code → You could still type it into a convincing fake page
- Passkey → Only works on the real site, so phishing can't use it
- Backup codes → Your way back in if you lose your phone
NO PASSWORD AT ALL
Passkeys
A passkey replaces the password with a secret key stored on your device. You unlock it the way you unlock your phone: fingerprint, face or PIN. The website keeps only a matching public half, which is useless to a thief if the site leaks. And your device will only use the passkey on the real site it was made for, so a fake page gets nothing.
More and more big services offer "Sign in with a passkey". Where you see it, it's usually the safest option on the list, and the fastest.
Check yourself
Ben gets a call from someone who says they're from his email provider's security team. They need him to read out the 6-digit code they just sent, to confirm it's really him. A real security team might do this.
Show the answer
False
False. A login code proves to the website that you're the one logging in. Nobody from a real company needs you to read it to them, and anyone who asks is trying to log in as you right now. Hang up, and never share a code.
YOUR MESSENGERS
Give your messenger a second lock
Telegram and WhatsApp log you in with a one-time code, often by SMS, so on its own your account is only as safe as that code. Both offer an extra setting called two-step verification: Telegram asks for a password you choose, WhatsApp for a 6-digit PIN, after the code. With it on, a stolen code isn't enough. While you're there, check the list of active sessions or linked devices and remove any you don't recognise.
Someone tricks Parisa into sharing her Telegram code. Because she set a two-step password last month, the attacker hits a password screen and can't get in.
Turn it on today, in this order
- 1 · Email
Use an authenticator app or passkey if offered. Save the backup codes.
- 2 · Messengers
Set Telegram's two-step password and WhatsApp's PIN. Remove unknown sessions.
- 3 · Password manager
Protect the vault that holds everything else.
- 4 · Bank and social media
Turn on whatever extra step each one offers.
Check yourself
Nazanin gets an SMS with a Telegram login code she never asked for. What's the best response?
- Type the code into Telegram herself to cancel the other person's attempt
- Keep it to herself and check her two-step password is on
- Reply to the SMS saying the login wasn't her
- Forward it to Telegram support through a link in the SMS
Show the answer
Keep it to herself and check her two-step password is on
Yes. An unrequested code means someone is trying to log in with her number. Keeping the code to herself stops them, and a two-step password stops them even if the code ever leaks.
Lesson recap
- Two-step login means a stolen password alone can't open your account.
- Strongest to weakest: passkey, authenticator app, SMS code, password only.
- No real company ever needs you to read a code out to them.
- Save backup codes, and set the two-step password or PIN on your messengers.