এই লেখাটির বাংলা সংস্করণ এখনো নেই — মূল ইংরেজি লেখাটি দেখানো হচ্ছে।
Two-factor authentication: the one security step everyone should take
Passwords leak. A second factor stops most account takeovers. Here is how 2FA works and which kind to choose.
Most account hacks do not involve clever code — they involve a password that was reused, guessed or leaked from another site. Two-factor authentication (2FA) adds a second check, so a stolen password alone is not enough.
The three kinds of factors
- Something you know: a password or PIN
- Something you have: your phone or a security key
- Something you are: a fingerprint or face
2FA combines two of these.
Your options, from weakest to strongest
SMS codes. Better than nothing, but vulnerable to SIM-swap fraud, where a criminal convinces an operator to move your number to their SIM.
Authenticator apps. Apps like Google Authenticator, Microsoft Authenticator or 2FAS generate a new six-digit code every 30 seconds on your phone. They work offline and are much harder to intercept.
Passkeys and security keys. Passkeys let you sign in with your phone's fingerprint or face unlock, and are tied to the real website — so a fake login page cannot trick them. Hardware keys work the same way on a small USB or NFC device.
Where to turn it on first
- Your email — it can reset every other password
- Mobile banking and payment apps
- Social media accounts
- Cloud storage with your photos and documents
Don't lock yourself out
When you enable 2FA, most services give you backup codes. Save them somewhere safe — printed, or in a password manager. If you change phones, move your authenticator app before wiping the old one.
The bottom line
It takes a few minutes per account and blocks the most common attacks. If you do one thing for your online security this week, make it this.