academy.security.krd
4 min

The second lock

One setting that makes a stolen password almost useless.

What it is

Two-factor authentication means a password alone is not enough to get in. Something else is needed — a code, or a tap on your phone. Somebody who steals the password still cannot open the account.

It is the single most effective thing on this whole site, and it takes two minutes.

Which kind to choose

They are not equally good. In order:

  1. A passkey or a security key. The strongest, and increasingly the easiest — your phone or fingerprint becomes the second factor.
  2. An authenticator app. Generates a six-digit code that changes every thirty seconds. Works with no signal.
  3. SMS. Better than nothing, and much better than nothing. But a text can be intercepted, and a phone number can be moved to another SIM by someone who persuades a shop they are you.

If your bank only offers SMS, use SMS. Do not let the perfect option stop you from taking the available one.

Turn it on here first

  • Your email — everything else resets through it
  • Your phone account — because it protects the SMS codes themselves
  • Anything holding money
  • Any account whose loss would embarrass you

Save the recovery codes

When you turn it on you are given a list of one-time codes. These are how you get back in when you lose your phone. Write them on paper and put them somewhere you keep documents. Not in the phone. Not in the email account they unlock.

The most common reason people avoid this is fear of being locked out. The recovery codes are the answer to that fear. Save them and the fear goes away.

This site is automated and receives nothing — there is no inbox and nobody to reply. If you need help from a person, tell someone you trust. Everything here is free to read, copy and share.