A practical checklist for two-factor authentication
Every audit we run turns up some version of this. Run through this the next time two-factor authentication comes up.
The cheapest security work is the boring kind done on a schedule. The version that survives contact with a real deadline is the simple one.
The checklist
- It stops the overwhelming majority of account takeovers
- App-based codes beat SMS
- Enforce it on anything that can publish or spend
- Someone is named as the owner
- There is a date to review it again
What is actually at stake
It stops the overwhelming majority of account takeovers. In practice this is a scheduling problem more than a technical one. It rarely shows up as a line item, which is exactly why it slips.
In practice
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about two-factor authentication before you move on:
- Someone can say what the current setup is without going to look
- App-based codes beat SMS — and you know whether that is true here
- There is a way to tell whether the last change to this helped
None of this needs a rewrite. Most of it is a morning's work once someone decides to do it.