Home / Guides / 2FA authentication

What is 2FA and why you should turn it on

Updated: August 2026 · By César Cerrudo

A password roughly answers: "What do you know?"

Additional authentication tries to add another proof: "What do you have?" or "Who are you?"

That means that if someone steals your password, they may still be missing a second piece to get in.

An example

Suppose someone gets your email password through phishing.

Without a second protection:

stolen password → access

With additional authentication:

stolen password → second proof missing → attack made harder

It isn't invulnerability. It's adding a barrier.

Common methods

Depending on the service, there may be:

Not all of them offer exactly the same level of resistance. But for someone who today uses only a password, turning on a second protection is a major improvement.

Never share the code

A very common attack works like this:

  1. the attacker gets your password;
  2. they try to sign in;
  3. the system sends you a code;
  4. the attacker calls or messages you;
  5. they convince you to tell them the code.

The security system worked. The attacker then tries to hack the person, not the system.

That's why

If you receive a code you didn't request, don't give it to anyone.

Where to enable MFA first

  1. email;
  2. Apple/Google/Microsoft account;
  3. financial services;
  4. password manager;
  5. social media;
  6. work accounts.

Why email first? Because many other accounts depend on it to recover passwords.

Want to learn how to protect all your accounts, your family and your business?

DOWNLOAD A HACKER'S SECURITY GUIDE FREE →
César Cerrudo
About the author

César Cerrudo is a professional hacker and cybersecurity researcher with more than 25 years of experience. He helped secure technologies from Microsoft, Oracle, Twitter and IBM, and is the author of A Hacker's Security Guide, a free guide that helps people, families and organizations learn to protect themselves in the digital world.

DOWNLOAD THE BOOK FREE →