February 10, 2026
Multi-factor authentication: small steps, big results
Multi-factor authentication, or MFA, is a very powerful tool that helps keep your digital accounts safe. But, what does it actually mean?
The problem: passwords aren’t enough
In the old days, you just needed a password to get into an account. In the early days of the Internet, passwords were fine. The Internet was small, and the amount of information was pretty small. But as the Internet grew, we started putting more and more valuable information within a stone’s throw of a cybercriminal.
It turns out, hackers are really good at getting your passwords. They can try to “phish” them from you, or tricking you into giving them to you. Or, they can find passwords from data breaches.
The solution: the “two-step” process
Multi-factor authentication forces you to prove who you say you are using multiple methods, or factors. Even if your password gets stolen, multi-factor authentication will still protect the account.
What are “factors?”
Let’s start with what a “factor” even is. Generally, there are three types of factors: knowledge, possession, and identity. Let’s explore each of these in a little bit more detail.
- A knowledge factor is something that you (and only you) know. No one else should know your knowledge factor. Examples of a knowledge factor include a password, a passphrase, or a PIN.
- A possession factor is something that you (and only you) have. No one else should have this thing, and you should always have positive control of it. Examples of a possession factor include your phone, your laptop, or a physical security key (like a FIDO2 or YubiKey).
- An identity factor is something that you (and only you) are. No one else should have these traits. Examples of an identity factor include fingerprints, retina scans, or face scans.
The key behind multi-factor authentication is the combination of two (or all three) of these factors. With multi-factor authentication enabled, an attacker can’t get into your account, even if they have your password or steal your phone. They require the combination of the factors in order to unlock the account.
Why is it worth the extra 10 seconds?
It might feel annoying to stop what you’re doing to grab your phone and type a code, but it’s the difference between your account being safe or getting hacked.
If a hacker steals your password, they still can’t get into your account because they don’t have your phone or other second factor.
And, if you lose your phone, you can normally use a backup code to get back into the account.
Think of it like wearing your seatbelt in a car. Sure, it’s a tiny bit of extra effort, and it might not be comfortable at first. But, you get used to it, and if you get in a crash (a hack), it keeps you safe.