2FA stands for 2 Factor Authentication. If you’ve used bank software or accountancy systems you are probably familiar with the concept. You might even have a bank fob somewhere, or the Google Authenticator application on your phone. 
2FA

A few years ago, I wrote a blog article about how important it was to have strong passwords. This is still very much the case today. But now 2FA is becoming a lot more popular.

2FA stands for 2 Factor Authentication. If you’ve used bank software or accountancy systems you are probably familiar with the concept. You might even have a bank fob somewhere, or the Google Authenticator application on your phone. 

What you might not be aware of is that many other websites and service providers have also implemented 2FA in the last few years, Facebook and indeed LinkedIn are just two of the more popular sites to be using it. Office 365 also has 2FA and Microsoft now switch this on by default on all new accounts. I personally have at least 20 accounts on which I have enabled 2FA, or where it has been a requirement.

But why do we need it in the first place, I hear you ask.

Sadly, hackers and phishing campaigns are getting increasingly more efficient at getting hold of your information. Data breaches can also lead to passwords being exposed and consequentially other accounts then get compromised. Many of us use the same password on many sites (despite this not being the recommended things to do). I would therefore recommend, that if you value your data, you look at implementing 2FA wherever you are able to.

Adding in that 2nd challenge can really help to secure your accounts and prevents unwanted people from getting in. Having one that changes every 30 seconds makes it even more secure. You should remain vigilant though and never ever enter your password / 2FA codes into a site you don’t recognise.

What software do I use?

When you sign up for 2FA on websites you’ll more than likely be told you need to use Google Authenticator. But this is not actually the only application that supports 2FA. Nor is it the only one that is compatible with the site that is asking you to use the Google Application.

I myself use Twillio Authy. Unlike Google Authenticator it is not tied to a single smart phone, it is cloud driven and there are desktop applications available for both Mac and PC.  It is still very secure, and you do still need the smartphone app to set it all up in the first place. But once that is done it’ll sync with the desktop application or indeed applications. You can also turn off the “add a device” option once you’ve added all the computers you need the account on to secure the account.

I made the switch a while back and moved everything from Google to Authy. Having the desktop application means you can copy and paste into your browser, rather than fumbling around with the phone app and making sure you type the number in, in the right order etc. I find the apps too painful to use (on the phone) and having to fish out my phone or go and find it when I need to login is just painful! It does use your mobile number to identify you .It has a PIN (or Face ID/Fingerprint reader options on the iPhone/Android) and a master password that is used to encrypt your account details.

So, I feel the answer is yes, you should be using it!

The original article was published on LinkedIn here.

Martin

Facts on cyber security

Below is an infographic summarising the key stats, predictions and facts on Cyber Security. Here are the key facts on cyber security for 2022 Cybersecurity

Read More »

Run your business effectively and efficiently at all times

All your Computers is a local, friendly, professional service

We cover East to Croydon, West to Andover, South to Southampton and North to High Wycombe, and Beyond!