Cloud, Services and Security

What Is Two-Factor Authentication, and Why Does It Matter?

Two-step verification is signing in to a system in two steps: first a password, and then a one-time code sent to a phone or email, or generated in an app. Even if someone got hold of the password, without the second step they cannot get in.

Two-Factor Authentication2FAMFAMulti-factor authenticationOne-time codeOTP

Reading time: about 8 minutes

The Idea: Two Keys Instead of One

Almost every login to a system is based on a password. The problem is that a password is something you know, and anything you know can also be discovered: someone saw it over your shoulder, it was written on a note, or it was also used on another site whose data leaked.

Two-factor authentication adds a second step, of a different kind: something you have, usually your mobile phone or your email inbox. After you type your password, the system sends a short code, and only someone holding the phone can type it in.

The closest comparison is a safe deposit box at a bank that opens only with two keys. Someone who stole one key is still standing in front of a closed door.

It is important to stress: two-factor authentication does not replace a good password, it comes in addition to it. A weak password with a second step is still better than a weak password alone, but the right combination is a strong, personal password, plus a code.

The Three Types of Proof

In the security world, people talk about three types of proof that you are you:

  • Something you know — a password, a secret code, an answer to a question.
  • Something you have — a mobile phone, a card, a physical security key.
  • Something you are — a fingerprint, face recognition.

Real two-factor authentication combines two different types. A password plus a security question are two things you know, so it isn't truly two-factor. A password plus a code sent to a phone are two different types, and that does count.

When more than two steps are combined, it is called multi-factor authentication (MFA), but in most ordinary systems two steps are enough.

In practice, in most systems you will meet, the second step will be "something you have" — a code that arrives on your phone or by email. Biometric identification is more common on phones and computers themselves, and less on websites and management systems.

Why It Helps So Much

Most account break-ins are not done in sophisticated ways. They are done with leaked passwords, or with fake emails that ask you to "confirm your details". Someone who typed their password into a fake page has handed it over without knowing.

Two-factor authentication stops most of these cases. Even with the password in hand, whoever is trying to log in also needs the code sent to your phone, and they don't have it. In addition, when a code arrives that you didn't request, it is a warning sign: someone is trying to log in with your password, and it is time to change it.

There is also a quiet benefit: knowing that the account is protected by two steps lowers stress. When a suspicious email arrives or a password was exposed by mistake, there is time to handle it in an orderly way, instead of rushing to change everything in a panic. The second step buys you that time.

Where You Have Already Met It

Even someone who has never heard the term knows two-factor authentication from daily life. When you log in to the bank's website and get a message with a code, when your health fund sends a code before showing test results, or when you change details on the electric company's website — all of these are two-factor authentication.

The reason these organizations moved to it is simple: they saw that passwords alone don't hold up. The number of break-ins using stolen passwords grows every year, and the second step turned out to be one of the simplest and most effective protections.

Hence the logic of applying the same principle to an organization's management systems, such as the phone system's control panel, where changes affect all employees and all callers.

Ways to Receive the Code

There are several common ways to do the second step, and each has advantages and disadvantages:

MethodHow it worksAdvantageDrawback
SMSCode sent by text message to a mobile phoneAlso works on a kosher phone, no app neededDepends on reception; not as strong as other methods
EmailCode sent to the email inboxDoesn't require a mobile phoneOnly as strong as the security of the email inbox
Voice callThe system calls and reads out a codeAlso works on a landlineLess convenient, takes time
Authenticator appAn app on the phone generates a new code every half minuteStrong, works without receptionRequires a smartphone
Security keyA small device that plugs into the computerThe strongest of allOne more item to keep and not lose

For people who use kosher phones, SMS and email are usually the practical options. They are not the strongest, but they are still much better than a password alone.

What to remember when choosing: the best method is the one that employees will actually use. A very strong method that everyone looks for a way around protects less than a simple method that everyone works with without complaint. That is why many places start with SMS or email, and offer stronger methods to managers.

The One-Time Code

The code that arrives in the second step is sometimes called an OTP (One-Time Password). It is short, usually four to eight digits, valid for a short time — just a few minutes — and once you use it, it doesn't work anymore.

There are two important rules about this code: do not give it to anyone, not even to someone on the phone who presents themselves as technical support; and type it only on a screen that you opened yourself, after you typed your password. A trustworthy organization will never ask you to read out a code you received.

Trusted Device: Not Every Time

A common worry is that two-factor authentication will turn every login into a chore. Many systems have a solution for this: a trusted device. After you have logged in once with a code from a particular computer, you can mark that computer as familiar, and the next times you log in from it you won't be asked for a code, or only after a period of time.

That way, someone who works every day from the same office computer barely feels the second step. But someone who tries to log in from another computer, in another place, runs into it right away. And that is exactly the point: the protection kicks in precisely when something is unusual.

Of course, you should not mark as trusted a public computer, a friend's computer, or a computer that several people use.

What Happens When the Phone Is Lost

This is the first question everyone asks, and rightly so. If the code goes only to one phone, and that phone is lost or replaced, how do you log in?

Different systems solve this in different ways: a second method as a backup (for example both email and SMS), backup codes that you print and keep in a safe place in advance, or a system administrator who can reset the authentication for a user after verification.

The general recommendation: on the day you turn on two-factor authentication, also arrange a backup method. And when you change a mobile number, update the systems before you pass the old SIM card on.

Why It Matters Especially for a Phone System

A phone system's control panel is not just another account. Whoever logs in to it can change where the organization's calls go, hear recordings, and sometimes even set up outgoing calls to expensive destinations. That is exactly the kind of damage described in the article on telephone fraud.

So, wherever it is available, two-factor authentication is especially recommended for users with administrator permissions. Alongside it, it is also worth using additional layers: minimal permissions, personal passwords, and restriction by IP address.

Common myths

  • "We have nothing to steal" — every organization with a phone line is a target, because it can be used to make calls at its expense. You don't have to be a bank for this to happen.
  • "I have a strong password, so I don't need it" — a strong password doesn't help if you typed it into a fake page, or if the site where you used it leaked.
  • "It's too complicated for employees" — after the first week, most employees no longer notice, especially with a trusted device.
  • "With two-factor authentication it can't be broken into" — it makes it much harder, but not impossible. You still need to be careful, especially with requests to hand over a code.

An example from the field

A small chesed nonprofit received an email one morning that looked as if it came from the bank, with a link "to verify the account". The bookkeeper clicked and typed in her password. A few minutes later a message arrived on her mobile phone with a login code that she had not requested.

Here the second step did its job. Whoever stole the password could not get in without the code, and the unexpected message set off a red light for her. She called the bank, changed her password, and the matter ended without damage.

Without two-factor authentication, the password alone would have been enough. The difference between the two scenarios is one SMS message.

How to Prepare

Even before a particular system offers two-factor authentication, you can prepare:

  1. Make sure every user has an up-to-date email and mobile number — these are the channels the codes will arrive through.
  2. Switch to personal users — two-factor authentication doesn't work well with a shared password, because the code reaches only one person.
  3. Turn it on elsewhere — on the organization's email inbox, for example. If the email is protected, the codes sent to it are protected too.
  4. Explain it to the team — especially the rule: never give a code to anyone.

How it works with us at Kesher

At Kesher, two-factor authentication for logging in to the control panel is in development and is not yet available to customers. We won't write here when, or exactly what it will look like, until it is ready.

In the meantime, what already exists in the control panel is the Users and Permissions screen, where each person has their own user with the permissions they need, and login restriction by IP address, which lets you set that a user can log in only from addresses you approved.

These two layers, together with a strong personal password, already give good protection today. And if you have a question about login security, every question is answered by a person at our company.

FAQ

Does two-factor authentication work with a kosher phone?

When the code is sent by SMS — yes, because kosher phones receive text messages. Authenticator apps, on the other hand, require a smartphone.

What do I do if the code doesn't arrive?

Check reception, wait a minute, and request a new code. If there is a backup method, such as email, use it. And if nothing works, contact the system administrator.

Someone called and asked for the code I received. What should I do?

Don't give it, hang up, and change your password. A trustworthy organization will never ask for a one-time code that you received.

I received a code that I didn't request. Is it dangerous?

It is a sign that someone tried to log in with your password. Don't type the code anywhere, and change your password right away.

Do I have to type a code at every login?

Not necessarily. In many systems you can mark a regular computer as trusted, and then the code is required only from a new computer or after a period of time.

What is the difference between two-step and multi-step?

Two-step is two steps, usually a password and a code. Multi-step is a general name for two or more. In everyday use, people usually mean the same thing.

Is there two-factor authentication in the Kesher control panel?

Not yet. It is in development. In the meantime there are personal users, permissions, and login restriction by IP address.

Does two-factor authentication slow down work?

Very little. Typing a code takes a few seconds, and with a trusted device it is needed only rarely. That is a small price compared with the damage a hacked account can cause.

Which is better, a code by SMS or by email?

Both are much better than a password alone. SMS is convenient for someone who always has their mobile phone with them. Email suits someone who doesn't have a mobile phone available, as long as the email inbox itself is well protected.

Is two-factor authentication needed for the phone itself, for the extension?

Not in the same way. An extension connects to the PBX with registration details that are set on the device, not with a code on every call. Extensions are protected in other ways: strong registration passwords and restrictions on outgoing calls.

Back to the Knowledge Center — all terms

Want to hear how it would work for you?

Tell us how your phones work today — how many calls, who answers, what gets in the way — and we'll get back to you with an organized proposal.

Leave your details and we'll get back to you
077-921-9000