Appearance
Choosing one
- Authenticator app: a six digit code that changes every thirty seconds. Works offline, works on any phone, and it is the option most people should take.
- Security key: a physical key, or a passkey on your device. Phishing resistant in a way that codes are not, because the key checks which site is asking.
Backup codes
When you enable a second factor you are shown a list of one time codes. Each one works once.
Save them somewhere that is not the phone holding your authenticator app. When you need them, that phone will be the thing that is broken, stolen or wiped, and codes stored on it are codes you do not have.
A printed copy in a drawer is not old fashioned. It survives a dead battery, a lost phone and a factory reset, and it cannot be read from the other side of the internet.
Turning it off
You can, from Security, after confirming your password. We would rather you did not: an alias service holds the map between your addresses and the sites you use, which is a map worth stealing.
What a second factor does not cover
It protects sign in. It does not protect a mail app password or an API token you have already issued: those are separate credentials with their own list, and revoking them is a separate gesture. If you think something is wrong, revoke both.
