Skip to content
logo The magazine for digital lifestyle and entertainment
Security Social Media All topics
Guide

What Is Two-Factor Authentication and How Does It Work?

Two-Factor Authentication (2FA) Stock Image: Man holding smartphone with lock icon in front of laptop
Two-factor authentication enhances security Photo: Getty Images
Share article

February 22, 2023, 11:49 am | Read time: 3 minutes

The so-called two-factor authentication is now standard for logging into various online platforms. But what exactly does it mean, and how does the process work?

Sensitive information, such as personal data, must be protected online to prevent misuse by hackers. For this purpose, usernames and passwords are used. Users log in for online banking or to their accounts on Amazon, eBay, etc. Many online providers further enhance security with the so-called two-factor authentication (2FA). This involves an additional identification step that the online provider requires alongside entering a username and password. So, it’s not enough for the user to identify themselves with the typical login data. As the name suggests, a second query is initiated for 2FA when logging in.

Two-Factor Authentication for More Security

However, users do not have to enter another password. That would increase the complexity of password management rather than the security level. Instead, users must identify themselves through another method.

There are various options for this. If the user has entered the login data on a smartphone, the online provider might ask them to verify the entry using the phone’s fingerprint sensor.

Also interesting: How well does two-factor authentication really protect user accounts?

More on the topic

Authentication via TAN or App

Often, this verification is done through a separate device. For example, if users log in on a PC, the online provider sends an access code to their phone, which the user enters in the second step.

In online banking, a transaction number (TAN) is often used for this purpose. Alternatively, the user confirms their login with an app belonging to the online provider. Authentication can also be done via a chip card inserted into a PC reader.

Hackers Have a Hard Time with 2FA

The advantage of two-factor authentication using two different devices: It’s not enough for a hacker to steal the username and corresponding password, as the user’s smartphone would, for example, request authentication, which the user would naturally deny.

A hacker would need to obtain not only the password and username but also the phone–and consequently its access data. If authentication is done via fingerprint, they would need even more from the user. This makes two-factor authentication significantly more secure than other methods. However, if the main device for 2FA is lost, it’s important to act quickly. Through the provider, you can usually easily transfer the old number and everything associated with it to a new smartphone.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.