What is 2FA and why you should turn it on
Updated: August 2026 · By César Cerrudo
A password roughly answers: "What do you know?"
Additional authentication tries to add another proof: "What do you have?" or "Who are you?"
That means that if someone steals your password, they may still be missing a second piece to get in.
An example
Suppose someone gets your email password through phishing.
Without a second protection:
With additional authentication:
It isn't invulnerability. It's adding a barrier.
Common methods
Depending on the service, there may be:
- SMS codes;
- authenticator apps;
- phone notifications;
- security keys or devices;
- passkeys.
Not all of them offer exactly the same level of resistance. But for someone who today uses only a password, turning on a second protection is a major improvement.
Never share the code
A very common attack works like this:
- the attacker gets your password;
- they try to sign in;
- the system sends you a code;
- the attacker calls or messages you;
- they convince you to tell them the code.
The security system worked. The attacker then tries to hack the person, not the system.
If you receive a code you didn't request, don't give it to anyone.
Where to enable MFA first
- email;
- Apple/Google/Microsoft account;
- financial services;
- password manager;
- social media;
- work accounts.
Why email first? Because many other accounts depend on it to recover passwords.
Want to learn how to protect all your accounts, your family and your business?
DOWNLOAD A HACKER'S SECURITY GUIDE FREE →