Cybercriminals are constantly attempting to gain access to our professional and private resources. The methods and techniques most commonly used for this purpose include:
By implementing two-factor authentication, you make this task significantly more difficult for cybercriminals.
Authentication factors can be divided into three categories:
Two-factor verification involves using two elements belonging to different categories from those listed above.
For example, a configuration using a login and password along with security questions is not a proper two-factor authentication setup, as it uses two factors in the same category (something I know). Answers to security questions such as "What was the make of your first car?", "What city were you born in?", or "What is your favourite book?" can be very easily obtained by people in your close circle, from social media, or through unintentional disclosure during a conversation or informal correspondence. Additionally, questions like "What is your mother's maiden name?" are often used by institutions or service operators to verify personal data.
Depending on the sophistication and capabilities of the website, we can distinguish various types of multi-factor authentication:
Please note!
Remember to periodically check the authentication factors you use. This involves verifying, for example, whether the correct number for receiving SMS messages is still provided, whether you have the correct TOTP applications linked to your account, or whether only the methods you actually use are added.
In the case of TOTP applications and hardware keys, it is worth having an active application on at least two different phones or two hardware keys - in the event of losing one element (e.g., losing a hardware key or a phone with a TOTP app), you will still be able to access your account using the backup element.
Using two-factor authentication, you can protect access to your email, applications available via a web browser, as well as your private online accounts, such as social media, email, or e-commerce platforms (e.g., online stores).
Protecting a private account on the Facebook or Instagram platform using properly configured two-factor authentication will not only protect our profile from third-party access, but will also help spare us the negative emotions and stress that can arise when losing access – which can be even more severe if our account manages a social profile or conducts business activities.
Compromised accounts on social media platforms are used by cybercriminals for further extortion of data or financial funds, or to encourage taking advantage of a lucrative offer that is, in fact, a scam. Someone who has gained access to our account uses our profile (exploits our digital identity) to lend credibility to the falsehoods they publish. Additionally, those with access to our account possess tools that can encrypt private messages in such a way that the account owner is unable to read what was sent to our interlocutor.
Securing your private email account with two-factor authentication will also allow you to protect your digital accounts. Well-known email providers such as Google, Microsoft, and Wirtualna Polska offer their customers the option to enable 2FA.
A significant portion of online services requires us to provide an email address, which sometimes serves as a login and also performs an important function: it allows for password recovery in the event it is forgotten. When a cybercriminal gains access to our email account, they can easily reset the password to any service where our email address was provided during registration.
Please note! By using 2FA, you significantly minimise the risk of a cybercriminal gaining access to your professional or private resources, even if they discover your password. This is important because:
If a website or web application does not feature two-factor authentication, ensure that the password for this service is sufficiently complex, unique, and properly secured, for instance, stored in a password manager.