Chapter 4 of 10All chapters
Chapter 4 of 10
Two factor authentication
Something you have.
The ladder
Weakest to strongest: security questions, email codes, SMS codes, authenticator apps, push approval, hardware keys. Anything above a password alone is a large improvement.
- Enable it on email, banking and anything holding card details first.
- Save recovery codes offline when you set it up.
Push fatigue
Attackers spam approval prompts until someone taps accept. Number matching, where you type a code shown on screen, exists to stop this. Never approve a prompt you did not trigger.