01Evidence A

Enable two-factor authentication on email, payment, and social accounts; prioritize phone pop-ups over SMS codes

Two-factor authentication means an extra verification step beyond the password when logging in. Using a pop-up prompt on your phone that requires a single tap to confirm blocks over 90% of phishing and account theft attempts. In contrast, older verification methods such as answering questions like “Where did you log in last time?” or “What is your backup email?” only block around 10% of such attacks.

Cost

No cost involved. Each account takes just two to three min…

Benefit

Google analyzed 350,000 real-world account hijacking attempts. For authentication methods relying on device ve…

Cost

No cost involved. Each account takes just two to three minutes to set up once.

Benefit

Google analyzed 350,000 real-world account hijacking attempts. For authentication methods relying on device verification — such as phone pop-ups or physical security keys — over 94% of phishing-related hijacking attempts and 100% of automated hijacking attempts were prevented. These automated attempts involve bots using leaked passwords to try logging into accounts in bulk. For verification based on answering personal questions, only 10% of phishing attempts and 73% of automated attempts were blocked.

Original sources

Doerfler P, Thomas K, Marincenko M, et al. (2019). Evaluating Login Challenges as a Defense Against Account Takeover. The World Wide Web Conference (WWW '19). https://doi.org/10.1145/3308558.3313481

Open source link
Book note

The same study also found that these verification methods occasionally block legitimate users from accessing their accounts. 52% of real users failed to log in on their first try. However, 97% of them eventually gained access. It is recommended to enable this feature on email accounts first, as most other accounts allow password recovery via email.

My note