Account Security

What is Two-Factor Authentication (2FA)

What is Two-Factor Authentication (2FA)?

Two-Factor Authentication (2FA) is an extra layer of stronger security used to ensure that people trying to gain access to an online account are who they say they are.

The first ‘factor’ is when a user enters their username and password.

The second ‘factor’ requires the user to provide another piece of information, typically a code sent to their phone via SMS or generated by an authentication app.

Why is 2FA important?

2FA significantly reduces the risk of unauthorised access, helping ensure that only the authorised user has access to the account.

Even if a hacker manages to steal the password, they won’t be able to access a 2FA account without the second factor, such as a code from your phone. This adds an extra level of security, making your accounts much harder to compromise.

How does 2FA work?

Once you enter your password, a second factor is required for verification. This second factor is often:

  • A one-time code sent to your phone via SMS.
  • A code generated by an authenticator app (e.g. Google Authenticator).
  • A biometric factor, like a fingerprint scan.

What are the benefits of using 2FA?

  • Enhanced Security:
    Protects your account from unauthorised access, even if your password is compromised.
  • Preventing Phishing:
    2FA can prevent cybercriminals from accessing accounts using phishing tactics, as they would need the second factor.
  • Peace of Mind:
    Knowing your account is protected by an additional security layer reduces the risk of breaches.

Is 2FA required for all accounts?

While not all services require 2FA, it is highly recommended for sensitive accounts, including email, financial services, and company platforms.

Does 2FA replace the need for a strong password?

No, 2FA does not replace the need for a strong, unique password. It is an additional layer of security, and using a strong password is still a critical part of account protection.

Can I disable it later?

Yes you can disable it any time you are logged in from your profile settings page