You have probably been nagged to turn on “two-factor authentication” by your bank, your email, and half the apps on your phone. It sounds like hassle. Here is why it is actually the single most effective security upgrade you can make, and how to set it up without confusion.
The simple idea
Your password is one “factor,” something you know. Two-factor authentication adds a second factor, usually something you have: your phone. Logging in then requires both, like needing two keys for a safe deposit box.
Why does this matter so much? Because passwords leak. Data breaches dump millions of passwords onto the internet regularly, and if you have ever reused one (most people have), yours might already be out there. With 2FA on, a stolen password is useless by itself. The scammer in another country does not have your phone.
The three types you will meet
SMS codes. A text message with a code arrives when you log in. Easy and familiar. Not perfect (sophisticated criminals can hijack phone numbers), but dramatically better than nothing.
Authenticator apps. Apps like Google Authenticator, Microsoft Authenticator, or Bitwarden (which we supply as a partner and which can store your codes alongside your passwords) generate a new six-digit code every 30 seconds. More secure than SMS and works without phone reception. This is what we recommend where it is offered.
Push approvals. The “Is this you? Approve” popup on your phone, used by Google and most banks now. Easiest of all: tap yes if it is you, no if it is not.
Where to turn it on first
You do not need it on everything. Prioritise by damage potential:
- Email — the master key to resetting everything else
- Banking — most Australian banks offer or require it now
- myGov — your tax, Medicare, and Centrelink all live here
- Facebook/social accounts — hijacked accounts get used to scam your friends
- Anything storing payment details — Amazon, PayPal, your Myki or toll accounts
How to actually set it up
In most services it lives under Settings > Security (or “Password and security”). Look for “two-factor authentication,” “2-step verification,” or “login verification.” The setup takes two to three minutes: choose your method, scan a code or enter your number, save it, done.
Save your backup codes. Most services give you one-time recovery codes during setup. Save them somewhere safe (a screenshot in cloud storage, or printed in a drawer). These are your way back in if you lose your phone.
The annoyance is smaller than you fear
Most services only ask for the second factor on new devices or after you have been logged out, not every single day. And the moment a scammer’s login attempt gets blocked because they do not have your phone, you will be very glad those two minutes existed.
One warning sign to know
If you get a 2FA prompt or code that you did not trigger, that means someone has your password and is trying right now. Deny the request and change that password immediately.



