Glossary
2FA (two-factor authentication)
2FA (two-factor authentication) is a login method that requires two different kinds of evidence of identity — typically something you know, such as a password, plus something you have, such as a phone or security key — before access is granted.
Updated By PhoneBorn TeamEditorial policy
How it works
Authentication factors fall into three categories:
- Knowledge — a password or PIN.
- Possession — a phone that receives an SMS code, an authenticator app, a hardware security key or a passkey stored on a device.
- Inherence — a biometric such as a fingerprint or face scan.
2FA combines two different categories. A password plus a security question is still one factor (knowledge twice). When more than two factors can be combined, the broader term is MFA (multi-factor authentication).
A typical flow: you enter your password, the service asks for a second factor, and you approve a push prompt, tap a key or type a one-time password.
Comparing common second factors
| Second factor | Strength | Main weakness |
|---|---|---|
| SMS or voice code | Basic | Number takeover via SIM swap, delivery delays |
| Authenticator app (TOTP) | Good | Phishable if typed into a fake site; lost phone without backup |
| Push approval | Good | "Push fatigue" — approving prompts by reflex |
| Security key / passkey | Strong | Needs a backup key or synced device |
SMS 2FA remains common because it needs no extra app, and many services use the phone number for account recovery as well.
Why the phone number matters
If SMS is your second factor or recovery method, the number becomes part of the account's security. A common real-world failure is not hacking but loss: a prepaid SIM expires, a number is recycled to someone else, or you travel and cannot receive texts.
Practical rules: use a number you will keep long-term, save backup codes offline, and add a stronger factor where the service allows it. A PhoneBorn phone-number plan is a real mobile number that stays assigned to you as long as you renew — see keeping your number for 2FA. A single-use OTP number is not suitable for 2FA, because it cannot receive later codes.