Staying Safe Online: Scams, Passwords and 2FA Two-Factor Authentication and the SIM Swap Problem
3 / 5
Next
Two-Factor Authentication and the SIM Swap Problem ~15min

What 2FA does

It requires something you KNOW plus something you HAVE. A stolen password alone is then not enough to get in.

Not all second factors are equal

  1. Hardware key (YubiKey), strongest, effectively unphishable
  2. Authenticator app (Google Authenticator, Aegis), codes generated on your phone, no network needed. Excellent
  3. SMS codes, better than nothing, but vulnerable to SIM swap

SIM swap

Someone with enough of your personal details persuades a shop to move your number to their SIM. Your phone loses service; every SMS code now goes to them. This is a real and common attack in Kenya. If your phone suddenly loses network for no reason, treat it as an emergency and call your provider immediately.

Save the recovery codes

When you enable 2FA you are shown one-time backup codes. Save them somewhere offline. Losing your phone with no recovery codes has locked people out of their own accounts permanently.

Where to turn it on today

Email first. Then anything holding money, then social accounts. It takes about two minutes per account and prevents the single most common form of account theft.

Tasks
Preview