Two-factor authentication, or 2FA, uses two distinct factors to verify a sign-in. In a password-based flow, the additional factor may be a security key, authenticator app, trusted-device prompt, or SMS code. A passkey may replace the password and can provide multi-factor authentication when it combines possession of the device with local PIN or biometric activation.
Why 2FA matters
An exposed password may no longer be enough to open the account. This limits credential-stuffing and ordinary password theft. 2FA does not stop every attack: criminals can phish codes, steal sessions, abuse recovery, or persuade someone to approve a prompt.
Stronger methods
Properly configured passkeys and FIDO security keys are designed to resist ordinary phishing because the credential is bound to the legitimate service. Authenticator apps avoid reliance on the phone network. SMS codes remain better than password-only access for many users but are more exposed to phone-number takeover and real-time phishing.
Recovery is part of security
Save backup codes offline, register a secure backup method, and remove old phones and keys. Protect the recovery email and mobile-carrier account. Never approve a prompt or share a code you did not initiate.