Two-factor authentication
Plain definition. Two-factor authentication is a login safeguard that asks you to prove who you are with two different kinds of proof, such as a password plus a second factor.
Technical definition. In an October 2022 fact sheet, the US Cybersecurity and Infrastructure Security Agency (CISA) describes multifactor authentication as a security control that requires a user to present a combination of two or more different authenticators to verify identity for login. Those authenticators are “something you know, something you have, or something you are,” and if one factor, such as a password, is compromised, an unauthorized user still cannot get into the account without the second factor. CISA calls FIDO/WebAuthn the only widely available phishing-resistant form.
On this site
On this site, Two-factor authentication comes up in Can someone steal my crypto through my phone number (SIM swap)? and How do I secure my account on a crypto trading platform (security keys, withdrawal allowlists, alerts)?.
Source
Implementing Phishing-Resistant MFA (cisa.gov), read October 1, 2026.
