The password worked. Then the site asked for six digits. A text, an email, or a tiny app that refreshes like a microwave clock. The banner says this is extra security. The mechanism is plainer: the password was not enough, so the site wants a second piece of evidence that is harder to copy from a leak.
That is two-factor authentication. Also called 2FA, a verification code, an authenticator app, “the number we just sent.” Same idea. Something you know, plus something you have. On most consumer sites that means: password plus phone.
Stolen password lists are a commodity. If the second check only exists for thirty seconds on a device in a pocket, last year’s dump is not a key by itself. That is the whole trick. It is useful. It is also not a force field.
How the code happens
An SMS code is a one-time password the site texts to the number on file. You type it. The site infers that the person with the password also has the phone. The phone company is now part of the login. Texts can be read on a stolen handset, rerouted after a SIM swap, or harvested by a fake page that looks like the real site and asks for the code the moment it arrives. The code expires. It is still a secret you can be talked into pasting.
Email codes are the same trick with a different mailbox. If someone already reads that inbox, they have the second factor too. Using email to protect the email account is a circle with extra steps.
An authenticator app does not wait for a message. When 2FA is set up, the site and the app share a hidden number. Every thirty seconds the app does math with that number and the current time. The site does the same math. Matching digits mean the app is present. Nothing is sent to you in the moment. There is no text to intercept. The codes still work with the radios off. Lose the phone without backup codes and the account becomes a very quiet object.
Push prompts (“Is this you? Approve”) skip the typing. They also train people to tap Yes the way cookie banners train people to tap Accept. A prompt is only as strong as the habit of reading it. If the phone lights up while nobody is logging in, the answer is No, not muscle memory.
What it will not do
- Stop anyone from typing the code into a fake site. The fake site takes the password, takes the code, and signs in while a spinner pretends to load.
- Fix a password reused on twelve other services. It just makes that particular reuse less immediately fatal.
- Survive a lost phone if the backup codes were never saved. Those codes are the spare key. Leaving them in the same camera roll as concert tickets is a choice.
- Mean the company is careful. Plenty of sites add 2FA and still email a reset link that bypasses it. The second check only applies where they wired it.
- Turn a fingerprint on the same unlocked phone into a second planet. If the glass is already open, “something you have” and “something you are” are often the same slab.
Text versus the app
SMS is better than nothing and worse than the app. Prefer the app when the site offers it. Prefer a hardware key or a passkey when those exist: the secret stays on the device and will not type itself into a lookalike form. Passkeys are a different animal. Two-factor is the older sibling that still shows up as six digits and a countdown.
Backup codes look like junk: a list of eight-digit strings on a page nobody wants to print. They are the way back in when the phone is in a lake. Save them somewhere that is not the phone you just enrolled. If that sounds annoying, wait until the recovery form asks for a utility bill and a week.
A short test
If a page that just opened is asking for the code, and nobody just tried to log in, do not provide it. If a caller already knows the password and only needs “the number we just sent,” hang up. If the only 2FA on file is a text to a number that was ported last year, that is not a second factor. That is a forwarding problem.
Call it a second check on a door that still has a lock. Useful. Cheap. Not armor, and not a reason to paste a code into a box that appeared because a link was clicked in a hurry.
