Safety & lawIdea 1 · 2 min read

Turn on two-step verification for email, payments and social accounts; prefer an approval prompt to an SMS code

Grade A evidenceValue: Very high
In plain language

Two-step verification asks for something beyond your password to confirm that it is really you signing in. In the study cited below, a prompt on a trusted phone blocked more than nine out of ten phishing-based takeover attempts. Older checks, such as asking where you last signed in or what your recovery email is, blocked as few as one in ten.

MoneyNo cost
TimeQuick and easy
EffortLittle effort

What it takes

Free. Allow two or three minutes to set it up for each account.

What you may gain

Google examined 350,000 real account-takeover attempts. Device-based challenges, such as approving a prompt on a phone or using a security key, blocked over 94% of phishing-based attempts and 100% of automated attempts. Phishing tricks you into entering a password on a fake site; automated attacks try leaked passwords at scale. Knowledge-based challenges, such as questions about a previous login location or recovery email, blocked as few as 10% of phishing-based attempts and 73% of automated attempts.

Context & considerations

These checks can also lock out the rightful owner temporarily. In the same study, 52% of legitimate users failed their first attempt, although 97% eventually regained access. Start with your email account: it is the recovery route for many of your other accounts.

Research & references

Doerfler P, Thomas K, Marincenko M, et al. (2019). Evaluating Login Challenges as a Defense Against Account Takeover. The World Wide Web Conference (WWW '19). https://doi.org/10.1145/3308558.3313481