Tools · Passwords and sign-in
Turning on two-step sign-in
Two-step sign-in (also called two-factor or multifactor authentication) means a stolen password alone can't open your account. Turn it on for your most sensitive accounts first: bank, credit cards, email, social media, tax site and payment apps. Choose a passkey, security key or authenticator app over text codes when offered, because text codes can be stolen with a SIM swap. Save the backup codes somewhere safe, and never give a code to anyone who contacts you.
What to know
- Open the account's settings, then its security section. It may be called Security, or Password and Security. Source: CISA
- Look for two-factor authentication, two-step verification or multifactor authentication. It usually isn't on by default. Source: FTC
- Pick the strongest method offered. Security keys are strongest, because there's no code to steal. Authenticator apps like Google Authenticator, Microsoft Authenticator or Duo are safer than text or email codes. Source: FTC If a site offers a passkey, take it. Source: National Cybersecurity Alliance
- Save your backup codes. They let you sign in if you lose your phone or change your number. Each works once, and you can print them and keep them with your passport or other important papers. Source: Google
- Let it remember only your own devices, never a library or other public computer. Source: FTC
Two-step methods, strongest first
From the FTC and the National Cybersecurity Alliance. Source: FTCNational Cybersecurity Alliance
| Method | How it works | Weak spot |
|---|---|---|
| Passkey | A key stored on your device plus your face or fingerprint | Can't be guessed, reused or phished in the usual way |
| Security key | A small physical device you plug in or tap | Strongest; no credential for hackers to steal |
| Authenticator app | Makes a new code about every 30 seconds, or sends a push to approve | Safe from SIM swaps and email hacks |
| Text or email code | A one-time code, usually 6 digits | SIM swaps can steal texts; a hacked email exposes codes |
If it doesn't work
- Only text codes offered? Use them; it's better than nothing. Source: FTC
- Lost your phone? Sign in with a backup code, then set up two-step again on your new phone. Source: Google
- Account already hacked? Follow the FTC's steps to recover a hacked email or social media account. Source: FTC
- Account doesn't offer two-step at all? CISA suggests asking the company why not. Source: CISA
Good to know
Why a password isn't enough
Hackers phish for passwords, buy ones stolen in data breaches, and try them on your other accounts if you reuse them. Source: FTC
Three kinds of factors
Something you know (a password or PIN), something you have (a code or security key), and something you are (a fingerprint or face). Two-step uses two of the three. Source: FTC
Sources
- Federal Trade Commission Use two-factor authentication to protect your accounts
- Cybersecurity and Infrastructure Security Agency Turn on MFA (archived)
- National Cybersecurity Alliance Multi-factor authentication
- Google Company source: its own product instructions Sign in with backup codes
- Federal Trade Commission How to recover your hacked email or social media account
Lesson T3.2 · Last checked October 2, 2026 against the sources listed.
Find it online: