Knowledge · Check before you click or pay · 7 minutes
Two-factor authentication (2FA): what it is and how to use it
What two-factor authentication (2FA) is, whether it is secure, which app and method to pick, whether it costs anything and what to do if you lose your phone.
Last updated: October 6, 2026
What does 2FA mean?
2FA stands for two-factor authentication. Services also call it 2-step verification or two-step login. It all means the same thing: signing in requires two factors from different categories.
According to CERT Polska, the Polish national CSIRT, there are three categories: something you know (a password, a PIN), something you have (a phone with an app, a hardware key) and something you are (a fingerprint, your face). A password plus a security question is not 2FA, because both are knowledge. MFA (multi-factor authentication) is the broader term: 2FA is the variant with exactly two factors.
A 2FA code is a one-time code, usually six digits, that you get by text message or read from an app. In apps it changes every few dozen seconds. The code is for you only: nobody from your bank, the service or "technical support" should ask you for it.
Is two-factor authentication secure and effective?
Yes, it is one of the most effective account protections. In a Microsoft study (Meyer et al., May 2023) of Azure AD accounts, MFA reduced the risk of compromise by 99.22%, and by 98.56% where passwords had already leaked. The US agency CISA sums it up: not every method protects equally, but any MFA is better than none.
2FA is not unbeatable, though. CERT Polska notes that a text or app code can be phished just like a password, on a fake login page that instantly relays it to the real service. A code's short lifetime is only a minor obstacle. That is why reading the site address still matters alongside 2FA, as we explain in what phishing is and how to spot it.
Does two-factor authentication make an account less secure?
No, that is a myth. The second factor adds a hurdle: someone who knows only your password cannot get in. Google puts it plainly: turning off 2-Step Verification removes an extra layer of security and makes it easier for someone else to access your account.
There are two real risks, and both can be managed. First, losing access when you lose your phone. The fix is backup codes and a second method saved in advance. Second, number hijacking (SIM swap) when the second factor is a text message. According to CERT Polska, a frozen PESEL (Polish national ID number) blocks the issue of a duplicate SIM card in Poland, and important accounts are better switched from text messages to an app, a passkey or a key.
Which authenticator app should I use? Types of methods
Rather than a brand ranking: choose a type of method, from strongest to weakest in terms of phishing resistance.
1. A passkey or a hardware key (FIDO2). According to CERT Polska and CISA, this is the only widely available method that resists phishing, because it is bound to the site address. A hardware key is a small device you plug in or tap against your phone. CERT Polska advises having two: one for daily use and a spare at home.
2. An authenticator app. It generates codes on your phone without the mobile network. Google, Microsoft and other vendors offer such apps, and on iPhone the built-in Passwords app can store codes too. Download only from the official store and check that the app lets you move codes safely to a new phone.
3. An in-app notification (push). Convenient, but CERT Polska warns that someone who has just typed their password on a fake site expects a confirmation prompt and approves it easily. Never approve a sign-in you did not start.
4. A text message code. The weakest option: NIST SP 800-63B-4 (August 2025) classifies codes sent over the phone network as a restricted authenticator. Still better than a password alone.
How to turn on 2-step verification in Google, Facebook and other services
Google Account and Gmail: open your Google Account, go to Security & sign-in and choose Turn on 2-Step Verification. Google lets you use prompts, passkeys and security keys, authenticator apps, text or voice codes, and backup codes.
Facebook, Instagram, X and LinkedIn: the option is in the account security settings. CERT Polska has collected instructions linking to each service's official help. In games, messaging apps, school e-registers and other services, look in the account settings for "2-step verification", "two-factor authentication" or "2FA".
Where to start: your email (because it resets your other passwords), banking, social media and your password manager account. More on combining it with a good password in how to create a strong password.
Lost or new phone: backup codes and transfer
Backup codes are one-time codes that let you sign in without your phone. Google issues a set of 10 eight-digit codes. Each works once, and you can generate a new set at any time. Save them as soon as you turn on 2FA: print them, download them or keep them in your password manager. CERT Polska also accepts a sheet of paper hidden somewhere safe at home.
Changing phones with Google 2-Step Verification: if you are signed in to your Google Account in Google Authenticator, codes sync to the new phone automatically. Otherwise, move them manually: export codes on the old phone and scan the generated QR code on the new one. Do this before you wipe the old phone.
If the phone is lost: sign in with a backup code or a second method, remove the lost device from the account and add the new one. If the app's codes were not synced, Google notes you have to update 2FA settings in each service separately. If you have no method left, what remains is the official account recovery process, described in someone hacked my account: what to do.
Does 2-step verification cost money, and how do I turn it off?
You do not pay for it: in the services we describe you turn it on in account settings, and authenticator apps from major vendors are free. The only cost is a hardware key, if you choose one. Be wary of sites and messages that demand a fee to "activate security": you can check such a site's address for free.
You turn it off in the same place you turn it on. In Google: Security & sign-in, 2-Step Verification, turn off. Google warns that this removes an extra layer of protection and advises destroying saved backup codes. Instead of turning 2FA off because it is inconvenient, consider a passkey: you sign in with your fingerprint or face, with no codes to copy.
In short
- 2FA is a second factor alongside your password. A 2023 Microsoft study found it cuts the risk of account compromise by more than 99%.
- Passkeys and hardware keys are strongest, then authenticator apps, then push. Text messages are weakest, but better than nothing.
- A 2FA code is for you only. Do not type it on a page you reached from a link, and never give it to anyone over the phone.
- When you turn on 2FA, save backup codes and add a second method right away. That protects you from losing the account with your phone.
- Two-factor authentication is free. Do not turn it off for convenience: switch to a passkey.
Have a website, app or email address that looks suspicious?
Frequently asked questions
What does 2FA stand for?
Two-factor authentication, also called 2-step verification. You sign in with your password and a second factor, for example a code from an app.
What is the best authenticator app?
The type of method matters more than the brand: a passkey or hardware key resists phishing, and an authenticator app is a good standard. Pick an app from an official store that lets you move codes safely to a new phone.
Do I have to pay for two-factor authentication?
No. Popular services let you turn it on for free in account settings. Only a hardware key costs money, if you decide to buy one.
What do I do with Google 2-Step Verification when I change phones?
If Google Authenticator is linked to your Google Account, the codes move automatically. Otherwise, transfer them by exporting QR codes from the old phone before you wipe it.
Is a text message a secure second factor?
It is weaker than apps and passkeys, because the code can be phished and the number hijacked with a duplicate SIM. It is still better than a password alone.
Can I turn off two-factor authentication?
Yes, in your account security settings, where you turned it on. Google warns this makes takeover easier, so it is better to switch to a more convenient method than to turn it off.
Sources
- CERT Polska: Multi-factor authentication (MFA) (in Polish)
- CERT Polska: How to create secure passwords and protect your accounts (updated 2 September 2026, in Polish)
- Meyer et al., Microsoft: How effective is multifactor authentication at deterring cyberattacks? (May 2023)
- CISA: More than a Password (MFA)
- NIST SP 800-63B-4: Authentication and Authenticator Management (26 August 2025)
- Google Help: Turn on 2-Step Verification
- Google Help: Sign in with backup codes
- Google Help: Get verification codes with Google Authenticator (transfer to a new phone)
Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.
See also
- How to create a strong password: length, examples, managers
- Someone hacked my account: what to do, step by step
- What is phishing and how to spot a fake text or email
- Online fraud in Poland: where to report it and get money back
- How to tell if your phone is hacked: signs and what to do
- Is public Wi-Fi safe? What protects you and when a VPN helps