Skip to content
Public preview

2FA on Every Important Account

Email + bank + social + cloud: 2FA required. SMS is weak — use Authenticator app or physical key.

30 min Intermediate

Goal

Add second layer after password, so one breach can't steal account.

Steps

  1. 1
    Install Google Authenticator, Authy, or 1Password (TOTP apps).
4 more steps locked

Expected Outcome

Immediate
Stolen password alone won't breach you.

Evidence base

School: Information Security

Founders: NIST · Google Security (2019)

Google's 2019 study showed 2FA blocks 99% of automated attacks and 96% of targeted phishing.

Keywords

Frequently asked questions

How long does "2FA on Every Important Account" take?
This exercise takes about 30 minutes, practiced solo in a Action format.
When will I notice the effect of "2FA on Every Important Account"?
Stolen password alone won't breach you. In the short term: You sleep easy even hearing about a site breach.
Is "2FA on Every Important Account" evidence-based?
Yes — it draws on Information Security (NIST, Google Security (2019)). Google's 2019 study showed 2FA blocks 99% of automated attacks and 96% of targeted phishing.
Is "2FA on Every Important Account" suitable for beginners?
Its difficulty level is: Intermediate. No external tools required — it can be practiced directly inside the app.

Subscribe for full access

Subscribe to Plus for full access to this practice and the whole catalogue, or try first — free, no sign-in, no commitment.

Interactive practice locked · 4 more steps locked

7 complete practices (one per domain) are free forever, no sign-in.

Enjoyed it? Gift a journey Gift a journey