Last week, I wrote about passwords, passkeys, and what we often misunderstand about so-called “modern” security. That article sparked a reflection — not just technical, but personal.

Until very recently, I was a long-time 1Password user. Then I jumped to Bitwarden, looking to save money. But the interface didn’t fully click. I realized I needed something simpler — and more consistent across my tools — so I moved again, this time to Proton Pass, where I now manage my digital life.

This may sound obsessive, but there’s a reason: about a year ago, my phone was stolen from my hands in Santiago. In just a few hours, I learned the hard way how fragile our digital setup really is. That story, I’ll save for later — but it triggered everything I’ve been shifting since.

One of those shifts? A serious upgrade in how I use Two-Factor Authentication (2FA).

This article continues the reflection from Passkeys vs Passwords. But today, we’re focusing on that invisible — often annoying — layer that sits between your password and the world: 2FA.


What is 2FA and Why It Still Matters

2FA (Two-Factor Authentication) is the idea that one key isn’t enough. You need a second proof that it’s actually you logging in — something only you can provide.

This “second factor” usually comes in one of three flavors:

  • SMS code to your phone

    • Pros: Easy to use, widely supported
    • Cons: Vulnerable to SIM swapping and interception
  • Authenticator apps (like Proton Pass, Bitwarden, Google Authenticator)

    • Pros: Secure, offline-capable, more private
    • Cons: Can be lost without proper backup
  • Hardware tokens (like YubiKey)

    • Pros: Maximum protection, phishing-resistant
    • Cons: Less convenient, needs to be physically available

Why does it matter? Because passwords — even good ones — can be stolen, guessed, or leaked. But combining them with a separate layer makes you exponentially safer. It’s like locking a door and needing a fingerprint to open it.


How I Use 2FA Now (And You Could Too)

Here’s my current system:

  • Proton Pass as my password manager and 2FA tool (with 2FA enabled for it!)
  • Encrypted backup of authentication codes (just in case)
  • Device recovery plan in case of loss or theft
  • Gradually removing SMS verification where possible

Is it perfect? No. But it’s much better than before — and I sleep better knowing that a stolen phone won’t automatically mean a stolen life.


Final Thoughts

Security isn’t something you notice when it works — only when it fails.

2FA lives in that in-between zone: not invisible enough to forget, not dramatic enough to fear. But it’s the layer that gives your password real power. And while it may slow you down by a few seconds, it could save you hours — or days — of regret.

Soon, I’ll share the full story of that phone theft, what was lost, what I learned, and how it changed how I relate to my digital self. But this week, let’s keep it simple: check your 2FA setup.