Skip to content

Cyber Dictionary

Two-factor authentication (2FA)

A login that requires two different kinds of proof — something you know plus something you have — so a stolen password isn't enough.

Two-factor authentication adds a second checkpoint on top of your password: something you know (the password) plus something you have (a phone app, a hardware key) or something you are (a fingerprint).

Even if your password leaks, the attacker still can't log in without the second factor. It's the single highest-impact thing most people can do for their accounts — and the thing they put off the longest.

Prefer an authenticator app or a hardware security key over SMS codes, which can be intercepted via SIM-swapping.