February 22, 2023, 11:49 am | Read time: 3 minutes
The so-called two-factor authentication is now standard for logging into various online platforms. But what exactly does it mean, and how does the process work?
Sensitive information, such as personal data, must be protected online to prevent misuse by hackers. For this purpose, usernames and passwords are used. Users log in for online banking or to their accounts on Amazon, eBay, etc. Many online providers further enhance security with the so-called two-factor authentication (2FA). This involves an additional identification step that the online provider requires alongside entering a username and password. So, it’s not enough for the user to identify themselves with the typical login data. As the name suggests, a second query is initiated for 2FA when logging in.
Two-Factor Authentication for More Security
However, users do not have to enter another password. That would increase the complexity of password management rather than the security level. Instead, users must identify themselves through another method.
There are various options for this. If the user has entered the login data on a smartphone, the online provider might ask them to verify the entry using the phone’s fingerprint sensor.
Also interesting: How well does two-factor authentication really protect user accounts?
No Spam! PayPal Announces Simplified Login Processes via Email
How Not to Register on Online Shops
Authentication via TAN or App
Often, this verification is done through a separate device. For example, if users log in on a PC, the online provider sends an access code to their phone, which the user enters in the second step.
In online banking, a transaction number (TAN) is often used for this purpose. Alternatively, the user confirms their login with an app belonging to the online provider. Authentication can also be done via a chip card inserted into a PC reader.
Hackers Have a Hard Time with 2FA
The advantage of two-factor authentication using two different devices: It’s not enough for a hacker to steal the username and corresponding password, as the user’s smartphone would, for example, request authentication, which the user would naturally deny.
A hacker would need to obtain not only the password and username but also the phone–and consequently its access data. If authentication is done via fingerprint, they would need even more from the user. This makes two-factor authentication significantly more secure than other methods. However, if the main device for 2FA is lost, it’s important to act quickly. Through the provider, you can usually easily transfer the old number and everything associated with it to a new smartphone.