Two factor authentication, often written as 2FA, requires a second proof of identity in addition to your password. Even if an attacker has your password, they cannot log in without the second factor. It is the most effective single protection you can add to an account.
The common methods, best first
- Authenticator app. An app on your phone generates a six digit code that changes every thirty seconds. Free, works offline, and not vulnerable to SIM swapping. This is the sensible default.
- Hardware security key. A physical device you plug in or tap. The strongest option and effectively immune to phishing. Worth it for administrator accounts.
- SMS codes. Better than nothing, but vulnerable to SIM swap fraud and to delivery failures when travelling. Use it only where nothing else is offered.
- Email codes. Only as secure as the email account, which is often the account being attacked.
Where to enable it
Priority order for a typical business:
- Your business email accounts. Email is the reset path for everything else, so it is the highest value target.
- Your domain registrar. Losing the domain loses the website and the email together.
- Website administrator accounts.
- Payment gateway and bank portals.
- Social media and advertising accounts.
Save your recovery codes
When you enable 2FA you are given backup codes. Print them or store them in your password manager, somewhere other than the phone that generates the codes. People lock themselves out by changing phones without transferring their authenticator, and recovery without codes is slow and sometimes impossible.
On your website
We can enable two factor authentication on WordPress administrator accounts as part of a security review or under a maintenance plan. The small friction at login is worth removing an entire category of attack.
To have it configured on your site, reply to your email thread or contact [email protected].