Skip to content Skip to footer

Two-factor authentication

Two-factor authentication (2FA) is a method of securing access to IT systems and data that requires two forms of identification. Most commonly, when using two-factor authentication, in order to log into a specific account, the user must provide a second factor in addition to their password.

Why are login and password not enough?

Cybercriminals are constantly attempting to gain access to our professional and private resources. The methods and techniques most commonly used for this purpose include:

  • Phishing messages, i.e., messages that impersonate trusted senders (individuals or institutions) - you can learn more about this threat in our article, among others.
  • Dictionary, brute-force, or other specialised attacks used to guess a password if it is not sufficiently complex.
  • Various types of software capable of intercepting passwords as we enter them, or stealing them, for example, from a web browser.
  • Data leaks that occur on the internet. (Many users reuse the same login and password combinations across numerous external and internal websites. If one application is compromised, it will not be difficult for a cybercriminal to attempt to gain access to, for instance, the email account of the user whose data has been exposed).

By implementing two-factor authentication, you make this task significantly more difficult for cybercriminals.


What are the components of two-factor authentication?

Authentication factors can be divided into three categories: 

  • something I know (e.g., login and password), 
  • something I have (e.g., a device with authentication codes), 
  • something I am (e.g., individual user characteristics – biometrics, such as a fingerprint). 

Two-factor verification involves using two elements belonging to different categories from those listed above.  

For example, a configuration using a login and password along with security questions is not a proper two-factor authentication setup, as it uses two factors in the same category (something I know). Answers to security questions such as "What was the make of your first car?", "What city were you born in?", or "What is your favourite book?" can be very easily obtained by people in your close circle, from social media, or through unintentional disclosure during a conversation or informal correspondence. Additionally, questions like "What is your mother's maiden name?" are often used by institutions or service operators to verify personal data. 


Popular Two-Factor Authentication Solutions and Best Practices

Depending on the sophistication and capabilities of the website, we can distinguish various types of multi-factor authentication:  

  • Entering a code from an SMS message is a very popular method, but easier for an attacker to intercept than the others listed here. To use this method, you simply need to provide a work or private number to which the access codes will be sent. 
  • Using one-time passwords that change at specific intervals, e.g., 30 or 60 seconds (known as TOTP, Time-based One-Time Password) – usually displayed in a mobile app or by a dedicated physical device. Most applications of this type for generating one-time codes can be obtained by downloading them from official stores that support mobile devices – free applications include Microsoft Authenticator or 2FAS, for example. Such apps do not require permissions to your photo gallery or contacts, thus they do not interfere with the data contained on your device. Only camera access may be optional for the purpose of scanning a QR code. 
  • Using a hardware "key" – this is a physical device, generally small in size. It resembles a flash drive or a wireless mouse receiver. Keys can be plugged into devices as well as used contactlessly. Unlike passwords sent via SMS and codes generated by applications, a hardware key cannot be remotely "intercepted" and used by a hacker, for instance in phishing attacks. There are many key models available on the market with varying degrees of sophistication. The most popular key manufacturers include Yubico and OnlyKey. 
  • An example of applying something I already have could be using our work computer as a second authentication factor by utilising the Windows Hello mechanism. To use this method, our device must be properly configured (e.g., by using biometrics and a strong PIN code), and also adequately secured (among other things, it must have an encrypted hard drive) to prevent unauthorised individuals from easily accessing this functionality in the event of loss.

Please note! 

Remember to periodically check the authentication factors you use. This involves verifying, for example, whether the correct number for receiving SMS messages is still provided, whether you have the correct TOTP applications linked to your account, or whether only the methods you actually use are added.  

In the case of TOTP applications and hardware keys, it is worth having an active application on at least two different phones or two hardware keys - in the event of losing one element (e.g., losing a hardware key or a phone with a TOTP app), you will still be able to access your account using the backup element. 


Why should you use 2FA?

Using two-factor authentication, you can protect access to your email, applications available via a web browser, as well as your private online accounts, such as social media, email, or e-commerce platforms (e.g., online stores). 

Protecting a private account on the Facebook or Instagram platform using properly configured two-factor authentication will not only protect our profile from third-party access, but will also help spare us the negative emotions and stress that can arise when losing access – which can be even more severe if our account manages a social profile or conducts business activities.  

Compromised accounts on social media platforms are used by cybercriminals for further extortion of data or financial funds, or to encourage taking advantage of a lucrative offer that is, in fact, a scam. Someone who has gained access to our account uses our profile (exploits our digital identity) to lend credibility to the falsehoods they publish. Additionally, those with access to our account possess tools that can encrypt private messages in such a way that the account owner is unable to read what was sent to our interlocutor. 

Securing your private email account with two-factor authentication will also allow you to protect your digital accounts. Well-known email providers such as Google, Microsoft, and Wirtualna Polska offer their customers the option to enable 2FA. 

A significant portion of online services requires us to provide an email address, which sometimes serves as a login and also performs an important function: it allows for password recovery in the event it is forgotten. When a cybercriminal gains access to our email account, they can easily reset the password to any service where our email address was provided during registration. 

Please note! By using 2FA, you significantly minimise the risk of a cybercriminal gaining access to your professional or private resources, even if they discover your password. This is important because: 

  • it prevents the theft or destruction of information located on a compromised account,  
  • it significantly hinders unauthorised individuals from sending messages from your email account to other people, 
  • keeping the information contained in your correspondence undisclosed to third parties helps avoid a targeted attack. 

What if 2FA is not available?

If a website or web application does not feature two-factor authentication, ensure that the password for this service is sufficiently complex, unique, and properly secured, for instance, stored in a password manager. 

Stopka