Identity Theft & Digital Identity
Multi-factor authentication
The single highest-value fifteen minutes in digital safety.
4 min readBeginnerIdentity
What You Need to Know
Multi-factor authentication requires a second proof beyond your password. App-based codes and passkeys are stronger than text messages, though any second factor is far better than none.
Why It Matters
It stops the overwhelming majority of automated account takeover attempts, even when your password is already public.
Warning Signs checklist
- Approval prompts you did not trigger
- Text codes arriving unexpectedly
- Recovery codes stored somewhere unsafe
- Your phone number is the only recovery option
How to Protect Yourself steps
- 1Enable it on email, banking, and social accounts first
- 2Prefer an authenticator app or passkey over text codes
- 3Store recovery codes in your password manager
- 4Never approve a prompt you did not start
Quick Checklist
- Enable it on email, banking, and social accounts first
- Prefer an authenticator app or passkey over text codes
- Store recovery codes in your password manager
- Never approve a prompt you did not start
Helpful Resources
- The Curiosity EditLong-form essays on cyber, AI, and everyday technology.
- Career GalaxyDiscover the careers built around this exact problem.
- Government resourcesOfficial reporting and recovery links, being verified before we publish them.
- Trusted nonprofitsCommunity partners offering free education and support, list in progress.
Follow the Rabbit Hole