Scams and staying safe
Two-factor authentication, explained without the jargon
You have probably been asked to set up “two-factor authentication” or “2FA” and either done it reluctantly or put it off. It is worth understanding, because it is the single most effective thing you can do to protect an account.
What it actually is
Normally an account asks for one thing: your password. If somebody has your password, they are in.
Two-factor authentication asks for a second thing, which is usually a short code that arrives on your phone. So getting in now requires both something you know (the password) and something you have (your phone).
That is the entire idea. It is not complicated, and the name is much more intimidating than the thing itself.
Why it matters so much
Passwords leak. Not usually because somebody guessed yours, but because a company you signed up to years ago was broken into and the list was stolen.
With two-factor turned on, a stolen password is no longer enough. Someone on the other side of the world has your password, tries it, and is then asked for a code that is sitting on the phone in your pocket. They cannot proceed.
It converts a stolen password from a disaster into a nuisance. That is a very large improvement for about five minutes of setup.
The kinds you will meet
A text message with a code. The most common, and the easiest to set up. It is also the weakest of the three, because determined criminals can occasionally take over a phone number. Still enormously better than nothing, and perfectly reasonable for most people.
An authenticator app. An app on your phone that generates a new six-digit code every thirty seconds. Free ones include Google Authenticator, Microsoft Authenticator and Authy. Stronger than text messages, because nothing is sent anywhere that could be intercepted. It also works with no phone signal, which is handy.
A prompt on your phone. Your phone buzzes and asks “is this you signing in?” and you tap yes. Common with Apple, Google and Microsoft accounts. Easy and secure.
Any of the three is a large improvement. Do not let choosing the best one stop you from turning on any of them.
Where to turn it on first
You do not need to do this everywhere at once. In order of importance:
- Your email. This is genuinely the most important account you own, because it can reset the password on almost everything else.
- Your banking. Most Australian banks now require some form of this.
- myGov, which reaches the tax office, Medicare and Centrelink.
- Anything with your card stored, such as Amazon, eBay or PayPal.
- Social media, particularly Facebook, which is heavily targeted for account takeovers.
The setting is usually under something like “Security”, “Sign-in” or “Two-step verification” in the account settings.
The part everybody worries about
“What if I lose my phone? Will I be locked out of everything?”
A fair concern, and there is a proper answer: backup codes.
When you set up two-factor, nearly every service offers you a list of one-time backup codes. These let you get in without your phone. Save them. Print them, or write them in a notebook, and keep them somewhere sensible at home. Not on the phone itself, which rather defeats the purpose.
If you skipped that step, go back into the security settings and generate a new set. It takes a minute and removes the entire worry.
It is also worth setting it up on two devices where you can, such as a phone and a tablet, so losing one is not a crisis.
One warning worth knowing
If a code arrives that you did not ask for, somebody is trying to get into your account right now. They have your password and are stuck at the second step.
Do not enter it anywhere. Do not read it out to anyone who rings you.
Instead, go and change that account’s password immediately, because the code arriving proves the password is known.
There is a scam built entirely on this: someone rings claiming to be from your bank or a delivery company and says “I have sent you a verification code, can you read it back to confirm your identity?” That code is the one thing standing between them and your account. Nobody legitimate will ever ask you for it.
No real organisation will ever ring and ask you to read out a verification code. Not one. If someone asks, they are stealing your account while you are on the phone to them.
Is it worth the hassle?
Yes, and honestly the hassle is smaller than people expect. Most services only ask for the code on a new device, or every few weeks, not every single time.
The trade is roughly ten seconds occasionally against the difference between a leaked password being a minor annoyance and being a very bad month.
If you would like someone to sit with you and turn it on properly across your important accounts, including saving the backup codes somewhere sensible, that is a straightforward single session. It pairs well with sorting out your passwords at the same time.