Two-factor authentication asks for something you know, like a password, and something you have, like your phone.
Why passwords aren't enough
Passwords leak in data breaches and get reused, so someone else may already know yours.
Codes and apps
The second step can be a one-time code by text message, a code from an authenticator app, or a tap on a trusted device.
Not all methods are equal
Authenticator apps and security keys are generally harder to intercept than text messages.
Never share the code
No bank or app needs you to read out a one-time code. Anyone asking for it is trying to get into your account.
Series · Part 2 of 4Tech, Plainly
Sources and corrections. This article draws on the sources listed here. Spotted a mistake? and we will correct it.
- 1 Sample source: background reference
- 2 Sample source: official or primary document
- 3 Sample source: explainer from another publisher (facts only)




