Dabish Digital
Security

A practical checklist for two-factor authentication

Every audit we run turns up some version of this. Run through this the next time two-factor authentication comes up.

The cheapest security work is the boring kind done on a schedule. The version that survives contact with a real deadline is the simple one.

The checklist

  • It stops the overwhelming majority of account takeovers
  • App-based codes beat SMS
  • Enforce it on anything that can publish or spend
  • Someone is named as the owner
  • There is a date to review it again

What is actually at stake

It stops the overwhelming majority of account takeovers. In practice this is a scheduling problem more than a technical one. It rarely shows up as a line item, which is exactly why it slips.

In practice

Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about two-factor authentication before you move on:

  • Someone can say what the current setup is without going to look
  • App-based codes beat SMS — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

None of this needs a rewrite. Most of it is a morning's work once someone decides to do it.