Two-Factor Authentication
- In Turkish
- İki Faktörlü Kimlik Doğrulama
In short
Two-factor authentication is a login method that requires two different kinds of proof, such as a password plus a code or security key, to confirm identity.
What is two-factor authentication?
Two-factor authentication, or 2FA, adds a second check to the login process so a stolen password alone is not enough to take over an account. The two proofs must come from different factor types: something you know, like a password; something you have, like a phone or hardware key; or something you are, like a fingerprint. Multi-factor authentication (MFA) is the general term for using two or more factors.
Common second factors include time-based one-time passwords (TOTP) from an authenticator app, which change every 30 seconds; push notifications to approve on a trusted phone; hardware security keys; and passkeys, which combine a device you have with a fingerprint, face scan, or PIN. Codes sent by SMS are better than nothing, but they can be intercepted or stolen through SIM-swap attacks, where a criminal convinces a mobile carrier to move your number to their SIM card.
2FA works like a bank card and its PIN: someone who finds your card still cannot withdraw money without the PIN, and someone who overhears your PIN still needs the card. Not all 2FA is equally strong, though, because attackers can trick users into typing one-time codes into fake login pages or flood them with push prompts until they tap approve. Phishing-resistant methods based on the FIDO2 and WebAuthn standards, such as security keys and passkeys, offer the best protection.
The terms 2FA, MFA, and two-step verification are often used interchangeably, although two-step verification can describe any extra login step, including weaker ones such as a code sent by email. When implementing 2FA, offer authenticator apps and passkeys rather than only SMS, store TOTP secrets encrypted, rate-limit code attempts, and give users one-time recovery codes for when they lose a device.
Key takeaways
- 2FA requires two different types of proof to log in.
- A stolen password alone is no longer enough to take over an account.
- Authenticator apps, security keys, and passkeys are stronger than SMS codes.
- Phishing-resistant methods based on WebAuthn give the best protection.
- Offer recovery codes and rate-limit attempts when implementing 2FA.
Example
// Step 1 passed (correct password); now check the 6-digit code
app.post("/login/2fa", twoFactorRateLimit, async (req, res) => {
const user = await db.users.findById(req.session.pendingUserId);
// TOTP secrets are stored encrypted; verifyTotp comes from a TOTP library
const secret = decrypt(user.totpSecretEncrypted);
if (!verifyTotp(req.body.code, secret)) {
return res.status(401).send("Invalid code");
}
// Both factors verified: finish the login
delete req.session.pendingUserId;
req.session.userId = user.id;
res.redirect("/dashboard");
});Readers ask
What is the difference between 2FA and MFA?
Two-factor authentication uses exactly two factors, while multi-factor authentication means two or more. In everyday use, the terms are often treated as the same thing.
Is SMS two-factor authentication safe?
SMS codes are much better than a password alone, but they can be stolen through SIM-swap attacks, phishing pages, or malware. Authenticator apps are stronger, and security keys or passkeys are the most resistant to phishing.
What happens if I lose my 2FA device?
Most services provide one-time recovery codes during setup that let you sign in and register a new device, so store them somewhere safe such as a password manager. Without recovery codes or a backup method, account recovery usually requires a slower identity check with the service.
See also
- AuthenticationSecurity, p. 2Authentication is the process of verifying that a user, device, or service really is who it claims to be, for example by checking a password or passkey.
- AuthorizationSecurity, p. 3Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- Rate LimitingBackend & APIs, p. 37Rate limiting is a technique that caps how many requests a client can make to a server or API within a time window, protecting it from abuse and overload.
- Zero TrustSecurity, p. 49Zero trust is a security model that trusts no user, device, or network by default and verifies every request based on identity, device health, and context.
Spotted a mistake or something missing on this page?Suggest an edit