Blog
What is two-factor authentication and how does it protect an account?
Most online shops, customer portals and mobile apps still protect accounts with a password alone, and that is no longer enough. Billions of passwords already sit in public breach lists, so every company that stores customer information needs an additional layer of security. This is why more and more businesses add two-factor authentication as a standard element on their own accounts and on customer accounts.
In this article we explain how it works, how it differs from multi-factor authentication and how a company can add it to its own system.
Why is a password no longer enough?
Many accounts are broken into not because the password is weak, but because it appears in a data breach list. These lists hold billions of email and password combinations. Attackers try them automatically, at thousands of login attempts per second, until one combination works.
This attack method is called credential stuffing. An attacker takes one or more leaked email and password combinations and tries them on other websites. Because people often reuse the same password across several services, a single breach can also put at risk every other account that shares that password.
According to Microsoft research, 2FA stops around 99.9 per cent of automated attempts to reach an account with leaked passwords. This check has become the standard in financial services, in e-commerce and in every system that holds important user information.
How does this verification work?
Once the user has entered their email and password, the system sends them a one-time password, or OTP, to their phone or email. This verification code creates an additional layer of protection. Even if the password has leaked, an attacker cannot reach the account without access to the user’s phone or email.
The user gains access to the account only after entering this code. The whole security check takes a few seconds.
What types of authentication are there?
Authentication falls into three types.
- A password or PIN code set by the user
- A mobile device or security key the user uses to confirm the login
- A biometric check, such as a fingerprint or face recognition
A password on its own is only one of these three types. 2FA adds one more check to the password, for example a code received on a mobile device, or a fingerprint. Companies that need more than this can choose multi-factor authentication, or MFA, which adds two or more extra checks to the password.
What is multi-factor authentication?
Unlike two-factor authentication, multi-factor authentication (MFA) requires identity to be confirmed with three or more checks, the password included. Even if an attacker has obtained both the password and the user’s phone, they cannot reach the account without a third confirmation, such as a fingerprint. A widely known MFA example in the Baltic states is Smart-ID, used for online banking and public services.
What is the main difference between 2FA and MFA?
Two-factor authentication (2FA) adds one extra check to the password, while MFA adds two or more. For most companies 2FA provides sufficient protection. MFA suits organisations where the consequences of a breach are larger, for example financial systems that move large sums of money, or internal company systems holding confidential data.
Where do companies use this protection?
The extra check is most often used in the following situations.
- Logging in to mobile applications and online services
- Signing in to online banking and financial systems
- Access to internal company systems
- Payment confirmation under the PSD2 SCA requirements
- Password reset requests
The level of risk differs in each of these cases, but the extra check protects the customer account even when the password ends up in the wrong hands.
How to add two-factor authentication to your system?
To add this protection to a system, a company needs to work through four questions in order.
How will the code be delivered?
The user can receive the verification code in several ways. SMS with a one-time code is the most common, because nothing has to be installed. The alternatives are authenticator apps, such as Google Authenticator or Microsoft Authenticator, and code delivery over WhatsApp when that channel suits the customers better.
How does the system integration work?
The company system connects to the SMS platform through an API. When a user signs in, the system generates a verification code, sends it to the user and then checks the answer.
What are the technical conditions?
The system has to keep the verification code valid for a short period, five minutes for example, and has to meet data protection requirements. It also has to let the user change the verification method at any time, for example from SMS to an authenticator app.
How to plan the user experience?
The system has to be clear the first time it is used, and the user has to know why the code is being requested. There also has to be a solution for cases where the user cannot reach their device, for example backup codes saved at the moment 2FA is set up, or account recovery through customer support. Without these, the protection can turn into an obstacle for the user.
Add extra protection to your system
NESS helps companies add 2FA and MFA to their systems through an SMS platform. We provide the API connection to the company system, fast message delivery and technical support. If you want to add 2FA or MFA for extra account security, contact us and we will prepare an individual offer for your system.