Staying Safe Online
Multi-Factor Authentication: The One Security Habit That Actually Matters
If you adopt exactly one security habit from everything we write, make it this one. Multi-factor authentication (MFA, or “two-factor”) stops the overwhelming majority of account-takeover attacks. That includes the ones where the crook already has your password.
What it actually is
A second checkpoint after your password: a code from your phone, a tap on a prompt, or a fingerprint. A password can be stolen from the other side of the world, but your phone is in your pocket. A thief needs both, and that combination defeats almost all of them.
Yes, it adds a step. Most services only ask for it on new devices, so in practice it’s a few extra seconds a month protecting everything you own.
Where to turn it on, in order
Don’t try to do everything. Do these four, in this order:
- Email. The master key. Whoever controls your email can reset every other password you have, which is why crooks go there first.
- Banking and investments. Most financial institutions now offer it prominently; some require it. Say yes.
- Anything with a card on file. Amazon, subscriptions, the app stores.
- Social media. Less about money, more about a hijacked account impersonating you to everyone you know.
Each takes about three minutes in the account’s security settings, usually under “two-step” or “two-factor” verification.
Which second factor to choose
Ranked from good to best. Every rung of this ladder beats not being on it:
- Text-message codes. Fine, and universally supported. The known weaknesses matter far more for high-profile targets than for the rest of us.
- Authenticator apps. Better, because the codes are generated on your phone and there’s nothing to intercept.
- The push prompt or passkey built into your phone. Best for most people. Nothing to type, and it resists the fake-login-page trick by design. When a service offers “sign in with your fingerprint/face,” take it.
One rule regardless of choice: save the backup codes the service offers when you set it up. Screenshot them, print them, put them where the passports live. They’re how you get in when your phone is lost. Not having them is the only painful MFA story we ever hear.
The scam to know about
Since MFA works, crooks now attack the human instead: a call or text claiming to be your bank, asking you to “read back the code we just sent.” No legitimate company ever asks you to speak a code aloud. The code arriving means someone is trying your password right now. Decline, hang up, and change that password today. (More of the current tricks in what’s going around Prescott.)
Want it all switched on in one sitting, with the backup codes filed properly? That’s one remote session. Ultimate members also get the layer beyond habits: a 24/7 security team watching for exactly the logins that shouldn’t be happening.