A password alone is no longer enough. If your password is stolen in a breach, 2FA is the only thing between an attacker and your account. But not all 2FA is equal. This guide shows you how to set it up properly.
Download Ente Auth from your app store. It's free, open-source, and offers encrypted cloud backups. Alternatives: Aegis (Android) or Raivo (iOS). Avoid Google Authenticator as a primary — it historically lacked backup features.
Your primary email is the master key — every password reset flows through it. Enable 2FA on your email provider first using your authenticator app. Do this before anything else because losing email access means losing everything else.
Copy the one-time recovery codes into your password manager as a secure note. Also print a physical copy and store it somewhere safe — a locked drawer or fireproof safe.
SMS is vulnerable to SIM-swapping. For every account using SMS 2FA, switch to authenticator app-based 2FA. Keep SMS only for services that offer no other option.
Enable app lock with biometrics or a separate PIN in Ente Auth's settings. Even if someone unlocks your phone, they still can't access your 2FA codes.
Enable cloud backup with end-to-end encryption in Ente Auth. Test by logging in on a second device to confirm your codes restore correctly — do this now, not when you've lost your phone.
Use your password manager's generator for every account — at least 16 characters, fully random. Never reuse passwords. One breached service with a reused password compromises every account sharing it.
After enabling 2FA, check "Active Sessions" in each account's security settings and log out anything you don't recognize. Make this a monthly habit. An unrecognized session means your account may have been accessed — change your password and rotate your 2FA secret immediately.
Setting up 2FA across dozens of accounts is tedious. In a session, we walk through your full account inventory together, prioritize by risk, and make sure every critical account is hardened.