Why two-factor authentication matters more than it looks
The version of this that works is simpler than the version most people imagine. Two-factor authentication is easy to treat as a detail, and that is exactly why it is worth a few minutes of attention.
The cheapest security work is the boring kind done on a schedule. The version that survives contact with a real deadline is the simple one.
Why this earns attention
It stops the overwhelming majority of account takeovers. There is a version of this that is over-engineered, and it is worth avoiding. Anything you cannot measure here, you are deciding by taste, which is fine as long as everyone knows it.
App-based codes beat SMS. It is worth being explicit about, because assumptions differ quietly. The failure mode is not doing it wrong, it is doing it once and assuming it stays done.
What to watch for
Enforce it on anything that can publish or spend. None of that requires a large budget, only a decision and someone to own it. Check it against what you would want a competitor's site to get wrong.
The short version
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about two-factor authentication before you move on:
- Someone can say what the current setup is without going to look
- App-based codes beat SMS — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Worth checking on your own setup before it becomes someone else's problem to fix.