Skip to main content
Book 07 · SecurityPage 46 of 50

Two-Factor Authentication

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/two-factor-authentication

In short

Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.

What is two-factor authentication?

Two-factor authentication, or 2FA, adds a second check to the login process so a stolen password alone is not enough to take over an account. The two proofs must come from different factor types: something you know, like a password; something you have, like a phone or hardware key; or something you are, like a fingerprint. Multi-factor authentication (MFA) is the general term for using two or more factors.

Common second factors include time-based one-time passwords (TOTP) from an authenticator app, which change every 30 seconds; push notifications to approve on a trusted phone; hardware security keys; and passkeys, which combine a device you have with a fingerprint, face scan, or PIN. Codes sent by SMS are better than nothing, but they can be intercepted or stolen through SIM-swap attacks, where a criminal convinces a mobile carrier to move your number to their SIM card.

2FA works like a bank card and its PIN: someone who finds your card still cannot withdraw money without the PIN, and someone who overhears your PIN still needs the card. Not all 2FA is equally strong, though, because attackers can trick users into typing one-time codes into fake login pages or flood them with push prompts until they tap approve. Phishing-resistant methods based on the FIDO2 and WebAuthn standards, such as security keys and passkeys, offer the best protection.

The terms 2FA, MFA, and two-step verification are often used interchangeably, although two-step verification can describe any extra login step, including weaker ones such as a code sent by email. When implementing 2FA, offer authenticator apps and passkeys rather than only SMS, store TOTP secrets encrypted, rate-limit code attempts, and give users one-time recovery codes for when they lose a device.

Key takeaways

  • 2FA requires two different types of proof to log in.
  • A stolen password alone is no longer enough to take over an account.
  • Authenticator apps, security keys, and passkeys are stronger than SMS codes.
  • Phishing-resistant methods based on WebAuthn give the best protection.
  • Offer recovery codes and rate-limit attempts when implementing 2FA.

Example

Verifying a one-time code after the password step (Express)javascript
// Step 1 passed (correct password); now check the 6-digit code
app.post("/login/2fa", twoFactorRateLimit, async (req, res) => {
  const user = await db.users.findById(req.session.pendingUserId);

  // TOTP secrets are stored encrypted; verifyTotp comes from a TOTP library
  const secret = decrypt(user.totpSecretEncrypted);
  if (!verifyTotp(req.body.code, secret)) {
    return res.status(401).send("Invalid code");
  }

  // Both factors verified: finish the login
  delete req.session.pendingUserId;
  req.session.userId = user.id;
  res.redirect("/dashboard");
});

Readers ask

What is the difference between 2FA and MFA?

Two-factor authentication uses exactly two factors, while multi-factor authentication means two or more. In everyday use, the terms are often treated as the same thing.

Is SMS two-factor authentication safe?

SMS codes are much better than a password alone, but they can be stolen through SIM-swap attacks, phishing pages, or malware. Authenticator apps are stronger, and security keys or passkeys are the most resistant to phishing.

What happens if I lose my 2FA device?

Most services provide one-time recovery codes during setup that let you sign in and register a new device, so store them somewhere safe such as a password manager. Without recovery codes or a backup method, account recovery usually requires a slower identity check with the service.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings