2FA
In short: “Two-factor authentication” — a login that combines two different kinds of proof (e.g. password + a code from your smartphone), instead of relying on just one.
In more detail: The three classic factor categories are knowledge (password, PIN), possession (smartphone, hardware token) and inherence (fingerprint, facial recognition). 2FA combines two of them — a stolen password alone is then no longer enough for an attacker. Common implementations: time-based one-time codes (TOTP, e.g. Google Authenticator), SMS codes (considered less secure because of SIM swapping) or hardware keys (e.g. YubiKey).
In Depth
TOTP: the most widespread standard
TOTP (time-based one-time password, RFC 6238) is today the most widespread 2FA standard for apps: during setup, server and smartphone app share a secret seed (usually transferred as a QR code, which internally encodes an otpauth:// URL). From this, combined with the current time, both sides calculate the same 6-digit code every 30 seconds — without an internet connection being needed:
Code = HOTP(secret, current_unix_time / 30)
Because both sides calculate the same code independently, no secret has to be transmitted at login — only the 6-digit code, which expires after 30 seconds anyway. Servers usually tolerate a small time window (e.g. the previous and next 30-second block) to absorb slight clock differences between server and smartphone, without weakening security significantly.
SIM swapping and the weakness of SMS
This makes TOTP more robust than SMS codes: with SMS-based 2FA, an attacker can use social engineering at the mobile provider to have the phone number transferred to their own SIM card (SIM swapping) and thus receive all of the victim’s SMS codes without possessing their device. In the 2010s, such attacks were the cause of several prominent cryptocurrency thefts, in which attackers deliberately targeted high-value victims (well-known investors, company founders) via compromised phone numbers. SMS 2FA is therefore now considered “better than nothing”, but the weakest common second factor — for several years now, NIST has explicitly recommended in its Digital Identity Guidelines not to use SMS as the sole second factor for security-critical systems.
Hardware keys and phishing resistance
The most secure 2FA factor is physical hardware keys following the FIDO2/WebAuthn standard (e.g. YubiKey): they perform a cryptographic signature directly on the device and are therefore resistant to phishing — even if a user enters their password on a fake login page, the hardware key doesn’t work there, because it cryptographically checks the domain of the real page (the private key is bound to the exact domain with which it was originally registered). TOTP codes do NOT offer this protection: an attacker who builds a convincing phishing page can forward the TOTP code entered by the user to the real page in real time (“adversary-in-the-middle” phishing) and thus log in despite 2FA — hardware keys close exactly this residual risk through domain binding.
Push notifications and MFA fatigue
A third, increasingly widespread variant is push notifications (e.g. Microsoft/Okta Authenticator): instead of typing a code, the user confirms the login with a tap on the smartphone. The drawback showed in real incidents (including Uber in 2022): attackers with a stolen password repeatedly triggered push requests until an annoyed user confirmed by mistake or out of exhaustion (“MFA fatigue” or “push bombing” attack). Modern implementations counter this with number matching (the user has to enter a number shown in the browser into the app, instead of just confirming).
Recovery and practice
Important for implementation: 2FA doesn’t replace the need for a strong first factor (password) — it’s an additional hurdle, not a replacement. Recovery codes (one-time backup codes, usually 8-10 generated during setup) are mandatory so that users don’t lock themselves out permanently if they lose their smartphone — they should be kept separately from the smartphone (e.g. printed out in a safe), otherwise the separation of the two factors is of no use in an emergency.
See also: Authentication, Identity