Home AI Threats Free Help Services About IT Support Contact Book Consultation →
Back to Free Help
30 minutes8 steps

Two-Factor Authentication Done Right

A password alone is no longer enough. If your password is stolen in a breach, 2FA is the only thing between an attacker and your account. But not all 2FA is equal. This guide shows you how to set it up properly.

1

Install Ente Auth (open-source authenticator)

Download Ente Auth from your app store. It's free, open-source, and offers encrypted cloud backups. Alternatives: Aegis (Android) or Raivo (iOS). Avoid Google Authenticator as a primary — it historically lacked backup features.

2

Migrate your email account first

Your primary email is the master key — every password reset flows through it. Enable 2FA on your email provider first using your authenticator app. Do this before anything else because losing email access means losing everything else.

3

Store backup codes in your password manager

Copy the one-time recovery codes into your password manager as a secure note. Also print a physical copy and store it somewhere safe — a locked drawer or fireproof safe.

Warning: Never store backup codes in a plain text file on your desktop, email drafts, or an unencrypted notes app.
4

Remove SMS 2FA where possible

SMS is vulnerable to SIM-swapping. For every account using SMS 2FA, switch to authenticator app-based 2FA. Keep SMS only for services that offer no other option.

Priority order: Switch email first, then banking, then social media, then everything else.
5

Protect your authenticator app with a passcode

Enable app lock with biometrics or a separate PIN in Ente Auth's settings. Even if someone unlocks your phone, they still can't access your 2FA codes.

6

Set up encrypted backups of recovery keys

Enable cloud backup with end-to-end encryption in Ente Auth. Test by logging in on a second device to confirm your codes restore correctly — do this now, not when you've lost your phone.

7

Use secure generated passwords for each account

Use your password manager's generator for every account — at least 16 characters, fully random. Never reuse passwords. One breached service with a reused password compromises every account sharing it.

8

Monitor linked devices and active sessions

After enabling 2FA, check "Active Sessions" in each account's security settings and log out anything you don't recognize. Make this a monthly habit. An unrecognized session means your account may have been accessed — change your password and rotate your 2FA secret immediately.

Want help migrating all your accounts?

Setting up 2FA across dozens of accounts is tedious. In a session, we walk through your full account inventory together, prioritize by risk, and make sure every critical account is hardened.

Contact Us