Skip to content
Utah Community Learning

Text 2FA is fine, don't let anyone shame you out of it

About 20 minutes

Text 2FA is fine, don't let anyone shame you out of it

In the previous class we sorted out backup codes, so you can't lock yourself out the way I did. Today we're enabling the actual two-factor.

Before we begin, I want to preempt an argument. Someone always raises it, usually about ten minutes in, so let's address it now.

The argument

There's a whole contingent online — and, to be fair, some of them genuinely know their material — who will tell you that text-message codes are weak: that a determined attacker can sometimes hijack your phone number and intercept the code, and that you should use an authenticator app instead.

They're not wrong. Text codes are the weaker option, technically.

They're also missing the point.

Text 2FA is a hundred times better than no 2FA. And it's the version your uncle will actually enable, because he already knows how to read a text message. An authenticator app is one more app, one more setup step, one more thing to explain over the phone when he calls confused. Perfect security that nobody uses protects nobody. I'll take "good and enabled" over "excellent and abandoned" every single time.

So if you get overwhelmed today, or someone in your life gets shamed out of using text codes by a know-it-all nephew, send them back to me. Text 2FA. Fine. Settled. Moving on.

What 2FA actually is

One additional lock on the door. Your password gets you to the door; the code texted to your phone is the second lock. Someone in another state who steals or guesses your password still can't get in, because they don't have your phone sitting on your kitchen counter.

Setting it up, step by step

We're doing this live, one account at a time. Begin with email, because email is the master key to nearly everything else — if someone gets into your email, they can reset your other passwords through it.

  1. Open your email account settings. Look for "Security" or "Account settings."
  2. Find "Two-factor authentication" or "Two-step verification." Different services word it differently, but it's always in there somewhere.
  3. Choose "Text message" or "SMS" as the method.
  4. Enter your phone number. Your current one, not an old one you no longer check.
  5. It will send you a test code. Type it in.
  6. It will offer you backup codes at this point — screenshot them or write them down, as we practiced last time. Don't skip this. This is the step I skipped and paid for.
  7. Repeat for your bank, then anything with your name and address stored — Amazon, whatever you shop with most.

Do email, bank, and one shopping account today. That's sufficient for one sitting. We're not racing.

Where it gets tedious

You'll get a code every time you log in from a new device, and sometimes just periodically for no reason you can identify. That's the trade-off: a little friction for you, considerably more friction for anyone trying to get in as you.

If you travel and lose signal, or you switch phones and haven't set up the new one yet, that's what the backup codes are for. Print them. Store them somewhere you'd actually find them — not in the same email account they're protecting.

A word on the fine print

Here is what I actually want you to do, not merely nod at: when that code text arrives, read what it says before you type it in anywhere. Not just the six digits — read the sentence around them.

I got caught by this myself, briefly. I received a text that looked exactly like a parking-ticket notice — "unpaid citation, pay now to avoid penalty," link right there. I was already annoyed about it, already reaching for my card, all the way to the payment page. Then I glanced at the address bar out of habit, and the URL wasn't the city's site. It wasn't even close — just close enough that, had I been rushing, I wouldn't have looked. I backed out, no harm done, but it bothered me for a while, because I teach this class and I still nearly did it.

I tell you that one deliberately. Nobody in this room is foolish for almost clicking something. I have a class full of people who caught it, and exactly one man — me — who almost didn't.

The same principle applies to a fake 2FA text, which does exist. Someone texts you pretending to be your bank, saying "here's your verification code, reply with it to confirm your identity." That is not how real 2FA works. In real 2FA, the code travels from the company's system to your phone, and you type it into their website or app. You never read a code aloud or text it back to anyone. If a text is asking you to send the code somewhere, hang up on it exactly as you would a phone call.

Before next time

Set up email, your bank, and one shopping site with text 2FA before we meet again, and if you get stuck on a step, that's what the next class is for. Bring the confusing one and we'll sort it out together.

~kenneth

Text 2FA is fine, don't let anyone shame you out of it — Online Safety and Scam Prevention · Utah Community Learning