Two-Factor Authentication: Securing Your Digital Life (Part 2)

  • Author: Kyle Murphy
  • Posted: 20 Sept 2024
A green fingerprint icon beside the words Securing Your Digital Life and Two-Factor Authentication, with the Custom Code IT logo above.

Two-factor authentication (2FA) adds extra steps, or layers, of authentication on top of a traditional password.

Unfortunately, I commonly hear clients describe this extra step as "annoying", "too hard", "inconvenient" and "complicated".

Here's why you should protect your accounts with two-factor authentication, and how to reduce the friction of setting it up.

What's wrong with just a password?

If you just finished my article about password managers, you're now generating secure passwords for your accounts. So why do you need two-factor authentication?

You're off to a great start, but not out of the woods yet. There are many ways to steal a password, which makes them less secure than many think. Something as simple as someone watching you type a password at a cafe will do it. This is called shoulder surfing

We also blindly trust the companies we give our passwords to, hoping they'll do the right thing and store them properly. I have (on more than one occasion) been emailed my password in plain text, just in case I wanted to save it. With one well-executed attack, all of those mishandled passwords could be out in the public for anyone to use.

Even more embarrassing is copying your password from your password manager and accidentally pasting it somewhere it shouldn't go. I have definitely sent a password or two in an accidental Teams chat or SMS.

Having two-factor authentication doesn't stop these things from happening, but it makes it much harder for people to get into your accounts if your password is leaked.

What is 2FA?

If we break down the term two-factor or multi-factor (as it's also known), we are interested in authentication factors. You can enable extra factors on your accounts; think of these as extra pieces of evidence you must supply before you can access an account or service.

Each account might allow you to configure a range of factors. They can be grouped into the following categories:

  • Something you know: things like passwords and PIN codes.
  • Something you have: a device like your phone, a security key like a YubiKey, or even a swipe card for a door.
  • Something you are: attributes tied to you as a person, like your retina or fingerprints.

None of these factors is very secure on its own, but together they make an account much harder to get into.

If you consider a real-world scenario like opening a bank account or applying for a loan, it's not enough to say "I'm Bob"; you also need to provide several other factors, like a birth certificate and bank statements, to prove you are who you say you are.

One-time passwords (OTP)

Most people have encountered this type of two-factor authentication. You sign in with your password and are prompted for a code to complete the sign-in process.

This code can be retrieved from a physical authenticator device, a mobile app, or even via SMS or email.

One-time passwords work well because, as the name suggests, each password can only be used once. They can also be time-sensitive, which adds a further layer of security.

How OTPs work, and how they are generated at a cryptographic level, is outside the scope of this article.

A note about SMS

Possibly the worst of the additional factors, SMS two-factor authentication should only be used when you have no other options. Sending authentication codes over SMS leaves you susceptible to SIM swap attacks.

This is where an attacker can contact your mobile carrier and impersonate you to get a new SIM card issued.

This allows an attacker to steal your phone number and intercept any codes sent to your number.

Even changing your phone number (on purpose) without realising the implications could prove devastating if there's no other way to access your account.

Using SMS also makes it hard to share your codes with others, like within an organisation.

2FA in your password manager

Storing OTPs in your password manager is a great way to securely share credentials with members of your organisation, or with a partner or spouse.

It reduces the friction associated with setting up 2FA on your accounts because you only need access to your password manager.

A common objection to storing your 2FA codes in your password manager is that both factors end up in the same location.

My counterargument is that your password manager should also have 2FA enabled (you'll need a separate app or key), so if someone manages to get your master password and your 2FA code, you have much bigger problems.

Enable it everywhere

A password alone is no longer enough to keep your online accounts safe.

Enable two-factor authentication anywhere you can, and you've given the bad guys another hoop to jump through to reach your accounts and data.

Multi-factor authentication is a big topic, and I have only scratched the surface.

Can I help?

If you need help setting up two-factor authentication or a password manager, or want to discuss something else, get in touch.

Sources

Kyle Murphy

Make Cyber Security a Priority in Your Business

Practical cyber security steps for your business, from two-factor authentication and password managers to offboarding, device security and training.

  • cyber security
  • two-factor
  • password managers
  • security
  • guide
  • 2fa

Kyle Murphy

Helping NDIS Providers Succeed

Websites, software, business email, document storage and print and social media design for NDIS providers across Australia, from Custom Code IT.

  • NDIS
  • websites
  • support
  • security
  • software

Kyle Murphy

Analysing a Real Spam/Phishing Campaign

I received a convincing spear phishing email. Here's how it worked, how it played on my emotions and how I spotted it.

  • security
  • phishing
  • emails

You made it this far, you should probably contact us.

Take a moment to celebrate, give that scrolling finger a break, then contact us because we'd love to hear from you.

0466 624 345

Tell us how we can help you.