CCamoCrypt
Glossary

Two-factor authentication (2FA)

Definition

A security method requiring two distinct proofs of identity from separate categories, such as a password plus a hardware key, before granting account access.

Two-factor authentication (2FA) strengthens login security by demanding two independent proofs of identity drawn from different categories: something you know (a password or PIN), something you have (a phone, authenticator app, or hardware key), or something you are (a biometric such as a fingerprint). Because a single stolen password is no longer enough, an attacker must also compromise a second, separate factor to gain access.

Why it matters

Passwords are routinely leaked, guessed, or phished, so a second factor is one of the highest-impact defences an ordinary user can enable. Not all second factors are equal, however. Codes sent by SMS can be intercepted through SIM swaps, and one-time codes typed into a fake site can be relayed by attackers. Phishing-resistant methods built on the FIDO Alliance and W3C WebAuthn standards bind a credential to the genuine website’s origin, so it cannot be replayed on a lookalike domain. For high-value cryptocurrency accounts this distinction is significant, because attackers routinely build convincing fake login pages to harvest both a password and a one-time code in real time.

Common misunderstanding

Enabling any 2FA is often treated as fully solving account security. In practice the method matters: SMS and app-based one-time codes are far weaker than hardware security keys or passkeys, which resist phishing by design. Two factors from the same category, such as two passwords or two security questions, do not count as genuine two-factor authentication because they can fail to the same attack.

See SIM swap, custodial wallet and multi-signature wallet.

Frequently asked questions

Are authenticator apps better than SMS codes?
Yes. App-generated codes are not tied to a phone number, so they resist SIM swaps. However, both can be phished if typed into a fake site; FIDO2 hardware keys and passkeys resist that too.

← All glossary terms

Note: CamoCrypt is security & education only — no prices, no predictions, no investment advice. Verify every address and contract yourself; we cannot recover lost funds and neither can anyone who contacts you claiming they can.