S
2026.07.12 · 6 MIN READ

Two-Factor Therapy: your first session

This post contains affiliate links. If you sign up through one, we may earn a commission at no extra cost to you. Mentioned: Bitwarden

Welcome to your first session. You don’t need to lie down for this one — just your phone.

Two-factor authentication (2FA) means proving it’s you with two different kinds of evidence: something you know (your password) plus something you physically have (your phone, a key). Two passwords isn’t 2FA. Neither is a password plus your mother’s maiden name, whatever your bank’s website seems to believe.

Here’s what the next ten minutes gets you: which accounts to do first, why the method your bank keeps texting you is the one to avoid, and the one setup mistake that quietly turns your two factors back into one. Nobody has to buy anything or learn what TOTP stands for.

Start with email, because email is the master key

Every other account you own has a “forgot password?” link, and every one of those links points at your inbox. Your email isn’t one account among many — it’s the account that can mint replacements for all the others.

Attackers know this better than users do. Most takeover stories start with someone quietly owning the mailbox and working outward from there, because it’s the cheapest possible position to attack from — including the 47-minute scramble to get a hijacked Instagram back, which started with exactly that.

So turn on two-factor authentication on your email first, tonight, before anything else. Then check the “recent activity” or “signed-in devices” screen while you’re in there, and sign out anything you don’t recognise — 2FA only stops new logins, and a session that’s already signed in doesn’t need to log in again.

Two-factor authentication over SMS is the version to avoid

SMS is the weakest second factor you can pick, and SIM-swapping is why. Nobody breaks any encryption here — an attacker talks or bribes a rep at your carrier into moving your phone number onto a SIM they control, and from that moment every code your bank sends arrives promptly, correctly, and directly to them.

An authenticator app fixes that problem completely: the code is generated on your device from a secret only it holds, and there’s no support rep anywhere who can hand it to someone else.

It doesn’t fix phishing, though. A six-digit code is still a string you can be talked into typing into a convincing fake, and modern phishing kits forward that code to the real site in real time while you watch a loading spinner. A hardware key or passkey is the tier above an app, because it’s bound to the domain it was registered for — the fake site asks, your device declines to answer, and there’s nothing left for you to type into the wrong box. Authenticator app for most things; a key or passkey for your email and your bank.

Should your 2FA codes live in your password manager?

Most password managers will generate these codes right next to the login, Bitwarden included on its paid tier — and it also ships a free standalone authenticator app, if you’d rather not pay for the convenience.

Be honest about the trade, though: keeping the password and the code in the same vault collapses your two factors back into one. A compromised vault hands over both at once, in a single motion. That’s a fine deal for the eighty accounts you barely remember creating. It’s a worse deal for email and banking — keep those two in a separate app, or on a key, so a leaked or breached password isn’t also a leaked second factor.

The version where the password goes away entirely

A passkey replaces the whole password-plus-code routine with a key pair: the private half never leaves your device, unlocked by your face or your fingerprint, and the site only ever sees a signature back.

There’s no shared secret to steal in a breach, no code to relay to a phishing site, and nothing for you to type into the wrong box at 11pm. It’s the same origin-binding trick as a hardware key, minus the hardware — our explainer on password managers covers where passkeys fit alongside everything else in the vault.

Turn one on wherever it’s offered. It’s strictly less work than what you’re doing now, which is not a sentence security writers get to use often.

Then work outward: bank, then whichever account would hurt most

Email done, the order stops being subtle. Do your bank next — it’s the account with the most immediate downside if it goes wrong, and most banks have supported 2FA for years even if they’ve never once mentioned it to you.

After that, whichever social account would hurt most in someone else’s hands. That’s not always the one you post to most; it’s usually whichever one has years of DMs, old photos, and enough personal detail to make a decent case for being you elsewhere.

Don’t try to do all of them tonight. Three accounts set up properly beats fifteen half-configured ones, and the ten minutes you have right now is enough for the two that actually matter before tomorrow morning.

Save your recovery codes somewhere that isn’t your inbox

If you lose your phone, recovery codes are what get you back in — so store them somewhere that losing that phone isn’t also a coin flip on losing the codes.

Print them and put the paper somewhere boring, like the folder with your passport. A password manager vault works too, as long as you can actually reach that vault from a second device — a recovery code locked behind the one app you can’t currently open isn’t a recovery code, it’s a rumour of one.

Either way, not in a text file named “codes.txt” on your desktop, and never in the inbox they’re supposed to get you back into.

One thing before you close this tab

Open your email provider’s security settings and turn on two-factor authentication with an authenticator app. Not the whole list, not your bank, not tonight’s grand security overhaul — just email, just now. Everything else in this post gets easier once that one account is locked.

Same time next week?