Telegram NewsSubmit game
How to use a two-factor authentication app to protect accounts Image Source: Yeastar

How to use a two-factor authentication app to protect accounts

George Tsagkarakis 5 min read
Contents 11 sections
We may include affiliate links in our content, meaning we could earn a commission—or receive blockchain-based assets—if you click a link and make a purchase or take a specific action. Additionally, we use generative AI to help draft and refine our posts for clarity and grammar. All content is fact-checked and reviewed by a human editor before publication.

A password on its own can’t protect your accounts if it gets stolen in a data breach or a phishing attack. A two-factor authentication (2FA) app fixes that. It adds a second step: you type a short code that’s generated on a device you control, so someone with only your password can’t get in.

This guide explains how authenticator apps work, how to pick one, how to link it to your accounts, and what to do if codes stop working or you change phones.

Why a password alone isn’t enough

For many online accounts, the password is the first security measure and sometimes the only one. Reusing passwords and falling for phishing attacks both make it more likely that a stolen password will be used to get into your personal data.

An authenticator app asks for a second code that it generates on its own, on your mobile device. Without that app or device, nobody can sign in, even if they have your password.

Turn it on first for your most important accounts, such as email, cloud storage and online banking. These are frequent targets because getting into them can expose your identity or your money.

Why an authenticator app is safer than SMS codes

When you turn on 2FA, the two most common choices are SMS codes and an authenticator app. Both add protection, but they don’t protect you equally.

SMS codes can be intercepted, or someone can hijack the account the messages go to. An authenticator app makes its codes on your device, so they never travel over the cellular network where they could be intercepted.

These codes are time-based one-time passwords (TOTP), meaning each code works once and usually changes every 30 seconds.

Understand the terms in your security settings

Your account’s security settings may use a few different labels:

  • Two-factor authentication (2FA): a second step after your password to confirm it’s you.
  • Multifactor authentication (MFA): often used to mean the same thing as 2FA, but it can include other methods such as biometrics or hardware tokens.
  • Authenticator app: the app on your phone that generates the time-based codes.
  • Backup codes: single-use codes you get when you set up 2FA, which you use to get back in if you lose your device.

Choose an authenticator app for Android or iOS

Pick an app that fits how you use your devices every day. Look for these features:

  • Easy setup
  • Organized account management, so many entries stay easy to find
  • Easy recovery options
  • Cloud backup, so you can restore your codes if you lose your phone (some apps only store codes locally on the phone)
  • Multi-device support, if you use more than one device
  • Offline access, so you can get codes without an internet connection

Set up 2FA with an authenticator app

The exact wording differs from service to service, but the process usually goes like this:

  1. Sign in to the account you want to protect and open its settings.
  2. Go to the security or authentication section.
  3. Choose the option to enable two-factor authentication.
  4. Open your authenticator app and scan the QR code shown on screen. If you can’t scan it, type in the manual code the service gives you instead.
  5. Enter the time-based code the app now shows to finish linking the app to your account.
  6. Give the entry a clear name in the app so you can tell which code goes with which account.
  7. Save the backup codes the service gives you somewhere safe.

Keep your backup codes safe

If your phone is lost or reset, getting back into accounts protected by an authenticator app can be hard. Backup codes are your way back in.

Each backup code works once. Store them securely and somewhere you can reach them, so you don’t get locked out of your accounts for good.

Move your codes when you change phones

Do this before you erase or give away your old phone:

  1. Use the authenticator app’s export or migration feature to move your accounts to the new phone, or set up 2FA again for each account on the new device.
  2. Check that the new phone gives you working codes.
  3. Erase the old phone only after that.

If you’ve already switched phones without moving your codes, use your backup codes or contact the service’s support team to get back into your accounts.

Fix authenticator codes that don’t work

If the service keeps rejecting codes from your app, your device’s clock may be out of sync. Turning on automatic time synchronization on your phone usually fixes this.

If you have more than one login with the same provider, it’s easy to type the code for the wrong one. Give each entry in the app its own name so you always pick the right code.

What to do if a service only offers SMS or email codes

Some services don’t support authenticator apps and only offer 2FA by SMS or email. In that case, use a strong, unique password and turn on the service’s other account recovery features.

If the service adds authenticator app support later, switch to it for stronger protection.

Check your 2FA setup regularly

Every so often, make sure 2FA is still turned on for your important accounts, that your backup codes are saved where you can reach them, and that a new device hasn’t broken your setup. Keeping this up reduces your risk from credential stuffing (attackers trying leaked usernames and passwords on other sites) and from phishing attacks.

Frequently asked questions

Is an authenticator app safer than SMS codes?

Generally, yes. SMS codes can be intercepted or the account they go to can be hijacked, while authenticator app codes are made on your device and never cross the cellular network.

What’s the difference between 2FA and MFA?

The two terms are often used to mean the same thing. MFA can also include other methods, such as biometrics or hardware tokens.

What happens if I lose my phone with my authenticator app on it?

Use the backup codes you saved when you set up 2FA to get back into your accounts. If you don’t have them, the service’s support team may be able to help.

Why does my authenticator app show the wrong code?

Your phone’s clock is probably out of sync. Turning on automatic time synchronization usually fixes it.

Share this article
George Tsagkarakis

George Tsagkarakis, known as Staycalm4now is a professional author in the crypto gaming industry since early 2018. He has experienced all the growth of Blockchain Gaming and helped multiple projects achieve their goals and established a player base. He is the co-founder of egamers.io and now the Founder and owner of CryptoGames.gg He is also the COO of MyStage, an…

More from Cybersecurity & Privacy

Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted