2. What 2FA Actually Is (and What It Is Not)
What 2FA Actually Is (and What It Is Not)
Two-factor authentication means proving who you are in two different ways: something you know (your password) and something you have (usually your phone).
A stolen password on its own then becomes useless.
The three common methods, from weakest to strongest
1. Text message (SMS). A code arrives by text. Better than nothing, but the weakest option: text messages can be redirected to an attacker's phone, and they can be read on a locked screen. Use it only when nothing else is offered.
2. Authenticator app. An app on your phone generates a new six-digit code every thirty seconds, or shows an "Approve / Deny" prompt. It works even without a signal, and the codes never travel through the phone network. This is what we recommend for everyone.
3. Security key. A small physical device you plug in or tap. The strongest option, normally reserved for administrators and company owners.
Turning on 2FA in one place does not turn it on everywhere. Your email, your bank, your accounting system and your remote access are separate doors, each with its own lock. Switching one on leaves the others exactly as they were.
Where it has to be switched on
When a cyber insurer asks whether you use multi-factor authentication, they do not ask once — they ask about each of these separately:
- Cloud accounts (Microsoft 365, Google Workspace)
- Backups
- Administrator accounts
- Remote access and VPN
- Access given to outside vendors
Answering "yes" on that form when it is only partly true can cost you the claim later.
No se permite comentar en este curso.