> ## Content Index
> Fetch the complete content index at: https://mwanjajoel.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# HACKED!! Protecting your online identity using Two-Factor Authentication
- URL: https://mwanjajoel.com/protecting-your-online-identity/
- Published: 2026-09-22T20:20:49.000Z
- Updated: 2026-09-22T20:20:49.000Z
- Description: Passwords alone can't protect you against online identity theft. Switch on two-factor authentication.
- Author: Mwanja Joel
- Tags: Technology, #Import 2026-09-22 14:25

Passwords are a basic security requirement when accessing resources that are protected and are for authenticated users only. Sadly, passwords alone are no longer enough to protect you from online intruders a.k.a hackers.

Let me explain what I mean using something we all understand: your front door.

A password is a lock on a door. A good lock keeps out someone who simply walks up and pushes. But a lock has one weakness that has nothing to do with how strong it is — if somebody gets hold of a copy of your key, the lock does not argue. It opens. It cannot tell the difference between you and a stranger holding your key.

That is exactly what happens when someone steals your password. The lock works perfectly. It just opens for the wrong person.

**TL:DR (Too Long: Didn't Read):** A password is one key. Two-factor authentication simply asks for a second key before letting anyone in usually a short code from your phone. So even if a thief has your password, he is still standing outside. Switch it on for your email first, then your money, then everything else.

![silver steel door handle bar](https://images.unsplash.com/photo-1584045446619-7146285c9811?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDI4fHxrZXlzfGVufDB8fHx8MTc5MDEwODA0NXww&ixlib=rb-4.1.0&q=80&w=2000)

Photo by [Calvin Hanson](https://unsplash.com/@calvinhanson?ref=mwanjajoel.com) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit)

## You already use two keys every day

Here is the good news. You have been doing this for years without calling it anything clever.

Think about withdrawing money from an ATM. You need two things. You need the **card in your hand**, and you need the **PIN in your head**. The card alone is useless a pickpocket cannot do anything with it. The PIN alone is useless too. A thief needs both, and getting both is much harder than getting one.

Mobile money works the same way. Somebody needs your actual SIM card *and* your PIN.

That is two-factor authentication. Two different kinds of proof. That is the whole idea. The technical name sounds frightening, but you have been trusting your savings to it for years.

## So why isn't my password enough?

Three reasons, and none of them are your fault.

**Companies get robbed, and your password goes with them.** When a big website is broken into, the thieves walk away with millions of passwords at once. Yours may already be sitting on a list somewhere, and nobody sent you a letter about it.

**Most of us reuse passwords.** If the same password opens your email, your Facebook and your bank, then one leak opens all three. The thief does not need to be clever. He just tries the same key in every door.

**People can be tricked.** You get a message that looks exactly like it came from your bank. It is urgent. It has their logo. You type your password into it. That page was never your bank. This is called *phishing* — fishing with bait, and the bait is your worry.

Notice that a longer password does not save you from any of these. That is the point. You do not need a better lock. You need a second one.

## The second key comes in three flavors

When you switch on two-factor authentication, the website asks how you would like to be asked. You will usually be offered one of three things.

**1\. A code sent by SMS.** After you type your password, a text message arrives with six numbers. You type them in. Simple, works on any phone, no app needed. It is the weakest of the three, but it is enormously better than nothing.

**2\. A code from an app on your phone.** You install a small free app — Google Authenticator, Microsoft Authenticator and Authy are the common ones. It shows a six-digit number that changes every thirty seconds, like a clock. You open it, read the number, type it in. It keeps working even with no network and no airtime, because the code is generated on the phone itself, not sent to it.

[Google Authenticator - Apps on Google PlayEnable 2-step verification to protect your account from hijacking.![](https://mwanjajoel.com/content/images/icon/favicon_v3-f2361d91-5a1f-441e-94f8-f34e2e1df007.ico)Apps on Google PlayGoogle LLC![](https://mwanjajoel.com/content/images/thumbnail/4qyuLCJkVpVfoIeu6b0ld6LkKzPHHby9ZilLbxhUZLK4f64o65oHGW-ZsuVe3LAWDVuIZpkQISmmVvA4-qnofw-s0-br30-a3543ed8-6534-4f9c-870e-6eaa9098d0a1.png)](https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en&ref=mwanjajoel.com)

[Google Authenticator App - App StoreDownload Google Authenticator by Google on the App Store. See screenshots, ratings and reviews, user tips, and more apps like Google Authenticator.![](https://mwanjajoel.com/content/images/icon/favicon-32-001429fa-7ca4-4815-ad49-f7ff6f33f794.png)App StoreGoogle![](https://mwanjajoel.com/content/images/thumbnail/1200x630wa-2b549eef-8fcd-408c-9a06-9f555ed9536c.jpg)](https://apps.apple.com/us/app/google-authenticator/id388497605?ref=mwanjajoel.com)

**3\. A small physical key.** A little device, about the size of a house key, that plugs into your computer or touches your phone. You tap it and you are in. This is the strongest option and the one I would give to somebody who is truly a target. For most people it is more than they need.

## Which should you choose?

Use the app if you can. Here is why, and this is the one part worth reading twice.

A determined thief can sometimes convince your mobile network that he is you and that he has lost his phone. The network helpfully moves your number onto his SIM card. Your phone goes quiet, and every SMS code meant for you now arrives on his handset. This is called *SIM swapping*, and it is not rare.

The app avoids this entirely. The codes never travel through the network, so there is nothing to steal on the way. They are made on your phone, in your hand.

But please hear me clearly: **SMS two-factor is still far better than no two-factor.** If your bank only offers SMS, take it. Do not let the perfect stop you from being safe today.

## Where to switch it on first

Do not try to do everything in one afternoon. Do these in order.

**Your email comes first.** Not your bank your email. This surprises people, so let me explain. When you forget a password, where does the reset link go? Your email. Your email is the spare key cupboard for your entire life. Whoever controls it can walk into every other account you own, one at a time, and lock you out. Protect it first.

**Then anything holding money.** Your bank, your mobile money, any shopping account with a saved card.

**Then WhatsApp and social media.** In WhatsApp it is called *Two-Step Verification*. Turn it on. People who steal WhatsApp accounts use them to ask your friends and family for money while pretending to be you.

The setting is usually under *Settings*, then *Security* or *Password and security*. Look for the words "two-factor", "two-step" or "2FA". If you cannot find it, type the name of the website and "two factor authentication" into Google and the company's own instructions will come up.

## "But what if I lose my phone?"

This is the right question to ask, and it is the reason some people never switch this on. There is a proper answer.

When you set it up, you will be shown a list of **backup codes** — eight or ten long numbers. These are your spare keys. Each one gets you in once if your phone is lost, stolen or dead.

Do not be clever about where you keep them. **Print them, or write them by hand, and put the paper where you keep important documents.** Your passport, your land title, your bank papers. Paper cannot be hacked from another country.

Do not save them as a photo on the same phone. If the phone is what you lost, the photo is gone with it.

## Something new worth knowing about: passkeys

You may start seeing the word *passkey* offered instead of a password. A passkey lets you sign in with the same fingerprint or face you already use to unlock your phone. There is no code to type and nothing to remember.

It is genuinely better, and it cannot be phished, because there is no password for anyone to trick out of you. If a site offers it, take it. If it does not, the app codes we talked about remain perfectly good.

## What it will actually feel like

Let me be honest with you, because I do not want you to feel misled.

It will add about ten seconds when you sign in on a new device. That is the entire cost. And most services only ask on a phone or computer they have not seen before, so on your own laptop at home you will rarely be asked at all.

Ten seconds, occasionally. Against somebody reading your email, messaging your children for money in your name, or emptying an account it took you years to fill.

I know which trade I would make.

## Do one thing today

Do not close this page and plan to do it later. Later has a way of never arriving.

Open your email account right now — just that one. Find Settings, then Security. Switch on two-factor authentication. Write the backup codes on paper and put them somewhere safe.

It will take you five minutes. Then the next time a thief somewhere gets hold of your password, he will type it in, wait, and get absolutely nowhere.

That is a good feeling. Go and get it.