WHAT IS 2FA?
2FA stands for 2-Factor Authentication. It sounds like a rather dull topic, and perhaps it is. It’s a topic everyone encounters on a daily basis. In fact, you’re already using 2FA. You just don’t realize it.
If you use online banking, you’re using 2FA. If you need to log in via DigiD, you’re also using 2FA.
OKAY….
Simply put, 2FA is an additional online identity check. You’d think a username and password would be enough to secure your Facebook or Instagram, but that’s no longer the case. The reason banks and major government agencies force you to use 2FA is because they know this traditional method isn’t enough to truly verify someone’s identity. That’s why they send a text message to your phone with an additional code (like ING does with TAN codes) or use tokens (like ABN-AMRO does with its e-identifier). This extra (annoying) step is necessary because a hacker can only log in to your bank if they also have your phone or PIN.
YES SO? WHY DO I NEED THAT FOR FACEBOOK OR MY EMAIL?
You might think it’s not that bad and that you don’t need 2FA for Facebook or email. But imagine how often people try to access your data.
To give you an idea, between September 23 and October 18, 2016, there were 21 attempts to access my email.
That’s an average of once a day. And they come from all over the world: China, Russia, the United States, Germany, Mexico, Vietnam, Korea, Brazil, Algeria, Japan, and Pakistan.
If you also use Hotmail/Live Mail, you can check it yourself by clicking this link. If you see anything you don’t recognize, it’s high time to take 2FA seriously.
OK, IT’S IMPORTANT! BUT TO GET A CODE EVERY TIME I LOG IN TO FACEBOOK OR EMAIL…
2FA doesn’t have to be a nuisance in your daily life, not at all. You only need to authenticate once per device. In other words, if you check your email on someone else’s computer, you’ll be prompted to complete that extra verification step (e.g., with your phone). 2FA is only annoying at first. After that, you’ll hardly notice it anymore. So you don’t have to constantly perform 2FA on your everyday devices like a laptop, PC, or tablet. The first time is the most important.
IT’S OKAY, I HAVE A VERY DIFFICULT PASSWORD.
Even if you have a password with capital letters, unusual characters, and numbers, it’s still not a matter of if it will be guessed, but when? Passwords can be cracked relatively quickly.
We all know you use the same password for multiple things. It’s just easier. In a world where you can log in to Facebook, Google, Apple, Microsoft, Snapchat, Instagram, Twitter, work, insurance, your mortgage, or your taxes, what’s the chance you use 11 different passwords for all these accounts? Often, all these accounts are linked to a single email address. So it’s no wonder hackers consider your email account so important.
WHAT DO I NEED TO DO TO ENABLE 2FA?
Most large companies already have 2FA. You just need to enable it (check your (email) account settings).
DO YOU HAVE ANY FURTHER TIPS?
It’s best to secure as many accounts as possible with 2FA. Make sure your email is secure. I would also recommend securing the accounts you use frequently on a daily basis. Things like:
- Facebook: because other applications are often linked to your FB account via Oauth
- Google: because of gmail and android.
- Apple: because of your iPhone, iTunes, iCloud, etc.
