1. What two-step verification is and why it protects you
Two-step verification (also called 2FA, two-factor authentication, or "double factor") adds a second check on top of your usual password. The idea is simple: the password is "something you know," but the second step also requires "something you have," like your phone, or "something you are," like your fingerprint.
This means that if someone gets hold of your password — for example, because you used it on a website that suffered a data leak, or because you fell for a phishing email — they won't be able to get into your account without that second element. It's the difference between a stolen password being a minor scare or a real problem with your email, photos, or banking compromised.
2. SMS, authenticator app, or physical key: the most common types
Not all two-step verification methods offer the same level of protection. The three most common are:
- SMS code. The service sends you a text message with a one-time code. It's the most widespread method because it doesn't require installing anything, but it's also the most vulnerable: techniques like "SIM swapping" exist, where an attacker can pose as you to your carrier and receive your SMS messages.
- Authenticator app (Google Authenticator, Microsoft Authenticator, Authy, and similar). It generates a numeric code that changes every 30 seconds directly on your phone, without relying on coverage or the carrier's network. It's much harder to intercept than an SMS.
- Physical security key (a USB or NFC key like a YubiKey). It's the most secure method, since it requires having the physical device in hand to log in. It's mainly used in professional settings or by users with very high security needs.
For everyday use, an authenticator app offers the best balance between security and convenience, and it's the option we recommend if your account allows it.
3. How to turn it on step by step for a Google account
- Sign in at myaccount.google.com with your account.
- In the side menu, click Security.
- Look for the "How you sign in to Google" section and click 2-Step Verification.
- Click Get started and confirm your password when asked.
- Choose the method you want to use as the second step: you can start with your phone number and later add an authenticator app as an additional or primary method.
- Follow the on-screen instructions, enter the confirmation code you receive, and click Turn on.
The process is very similar on most services: Instagram, Facebook, Amazon, or your bank have this option within their "Security" or "Privacy and security" settings.
4. Why it's better to use an authenticator app instead of just SMS
Many services turn on SMS as the default method because it's the easiest to set up, but it's not the safest. Besides the risk of SIM swapping, SMS depends on having coverage: if you travel or lose signal, you can end up unable to receive the code right when you need it most.
An authenticator app, on the other hand, generates the code on the phone itself, without needing a connection or phone signal. If the service you use allows it, we recommend setting up an authenticator app as your main method and leaving SMS only as a backup option.
5. Keep your backup codes somewhere safe
When you turn on two-step verification, almost every service offers to download or write down a list of backup codes: one-time-use codes meant to get you into your account if at some point you don't have access to your usual method (for example, if you've lost your phone).
Keep these codes somewhere safe that only you control: a password manager, a printed sheet kept at home, or a digital safe. Avoid leaving them in an unprotected note on your phone, in an unencrypted email, or in a text document that's easily accessible on your computer. Each code can only be used once, so if you use them all up, you can generate a new list from the account's security settings.
6. What to do if you lose access to your second factor
If your phone is lost or stolen and it was the device where you received your codes, don't panic: follow these steps.
- Use one of your backup codes to log into the account from another device.
- Once inside, go to the security settings and remove the lost device from the list of "Devices where you're signed in" or from the active verification methods.
- Contact your carrier to block the SIM card and prevent anyone from receiving your SMS if they recover it.
- Set up the second factor again on your new phone as soon as possible.
If you didn't save any backup codes, you'll have to go through the service's usual account recovery process (similar to recovering a forgotten password), providing as much information as possible to prove the account is yours. It can take a bit longer, which is why it's so important to save your backup codes from day one.