Most accounts taken over by someone else aren't taken by guessing the password. The password was already known, leaked from another service you once signed up to and reused here.

That's what makes a second step so useful. It turns a leaked password from a key into half a key.

Three forms, not equally strong

Codes by SMS. Easiest and weakest. A phone number can be moved to another SIM through a takeover scam, and the code can be requested by a fake page and relayed to the real site within seconds. Even so, SMS is far better than no second step. If it's the only option a service offers, use it.

An authenticator app. A six-digit code changing every thirty seconds, generated on your device without crossing the network. This is the right stopping point for nearly everyone: far stronger than SMS, immune to number takeover, and free.

A hardware security key or passkey. The strongest, and the only one that genuinely closes off fake pages, because it checks the site address itself and refuses to work on the wrong one. Worth it for your main email and anything holding money.

A sensible order

Turning it on everywhere at once won't happen. This order removes most of the risk quickly:

  1. Main email. First, without debate. Nearly every other account recovers through email, so whoever holds it can take the rest one at a time.
  2. Anything holding money: banking, digital wallets, and selling accounts.
  3. Accounts used to sign in elsewhere, such as the Google or Apple account you've used to register everywhere.
  4. Social media and business accounts, especially those used with customers.

The most-skipped part

This is the number one reason people abandon two-factor: the phone is lost, and they're locked out of their own accounts.

When switching it on, the service offers backup codes, usually eight to ten single-use codes. Save them then, not later:

  • In your password manager, if you use one.
  • Printed and kept somewhere safe at home. It sounds old-fashioned, and that's the advantage: it doesn't disappear with the phone.
  • Not in notes on the same phone as the authenticator app, because both vanish together.

Equally valuable: register a second device, such as a tablet or old phone, in the authenticator app. Then losing one device never becomes losing access.

A second step doesn't replace passwords

Two habits still matter, and one tool covers both:

  • A different password per service. This is what stops a leak in one place becoming a problem everywhere.
  • A password manager. Nobody remembers dozens of distinct passwords, and keeping them in a plain file is worse. Principles for strong passwords are in strong passwords, and they apply equally to accounts.

A password manager also gives protection people rarely notice: it won't fill a password on the wrong address. A fake page that fools human eyes doesn't fool an address check.

Scams that still get through

Two-factor closes a lot, but not everything. What still works usually goes through people rather than systems:

  • Fake pages that ask for the code. You enter password and code on a replica, and the scammer relays both to the real site immediately. The pattern is described in phishing over public Wi-Fi.
  • Repeated approval prompts. Notifications arrive over and over until someone taps approve just to make them stop. If a prompt arrives that you didn't start, reject it, then change the password.
  • Calls claiming to be staff asking for the code to verify you. No legitimate service asks you for a code. The pattern matches fake internet technician scams.

One rule closes all three: a code is for entering, not for giving. Anyone asking you for one, by call, message, or chat, is scamming you.

A once-a-year review

Once a year, on your main email and business accounts, check four things:

  • Devices still signed in. Sign out anything unfamiliar or no longer used.
  • Third-party apps with access. That list accumulates for years and is almost never reviewed.
  • Mail forwarding rules and auto-replies. These are what intruders leave behind to keep receiving copies of your mail after the password changes. Rarely checked by anyone.
  • Recovery numbers and addresses. Confirm they're still yours, especially if you've changed numbers.

For business accounts

Two additions apply when accounts are used by more than one person:

  • Don't share one login. Use separate accounts per person with appropriate rights. A shared login means nobody knows who did what, and revoking one person's access disrupts everyone.
  • Revoke access when people leave, as part of the exit process. The duty to protect customer data stays with the business owner, covered in personal data security and the PDP law. If something does leak, the reporting steps are in reporting a personal data breach.

For network equipment the principle is the same but the method differs, covered separately in default ISP router admin accounts and securing your home router.

Frequently asked questions

Why are SMS codes called the weakest option?

Because a phone number can be moved to another SIM through a takeover scam, and an SMS code can be requested by a fake page and relayed to the real site. Even so, SMS is far better than having no second step at all.

What happens if the phone with my authenticator app is lost?

You're locked out of your own accounts, unless you saved backup codes or registered a second device. That's why backup codes are saved when you switch this on, not later.

Which account should be secured first?

Your main email, because nearly every other account recovers through it. Whoever controls your email can take over almost everything else, one at a time.