Last week, I wrote about passwords, passkeys, and what we often misunderstand about so-called “modern” security. That article sparked a reflection — not just technical, but personal.
Until very recently, I was a long-time 1Password user. Then I jumped to Bitwarden, looking to save money. But the interface didn’t fully click. I realized I needed something simpler — and more consistent across my tools — so I moved again, this time to Proton Pass, where I now manage my digital life.
This may sound obsessive, but there’s a reason: about a year ago, my phone was stolen from my hands in Santiago. In just a few hours, I learned the hard way how fragile our digital setup really is. That story, I’ll save for later — but it triggered everything I’ve been shifting since.
One of those shifts? A serious upgrade in how I use Two-Factor Authentication (2FA).
This article continues the reflection from Passkeys vs Passwords. But today, we’re focusing on that invisible — often annoying — layer that sits between your password and the world: 2FA.
What is 2FA and Why It Still Matters
2FA (Two-Factor Authentication) is the idea that one key isn’t enough. You need a second proof that it’s actually you logging in — something only you can provide.
This “second factor” usually comes in one of three flavors:
-
SMS code to your phone
- Pros: Easy to use, widely supported
- Cons: Vulnerable to SIM swapping and interception
-
Authenticator apps (like Proton Pass, Bitwarden, Google Authenticator)
- Pros: Secure, offline-capable, more private
- Cons: Can be lost without proper backup
-
Hardware tokens (like YubiKey)
- Pros: Maximum protection, phishing-resistant
- Cons: Less convenient, needs to be physically available
Why does it matter? Because passwords — even good ones — can be stolen, guessed, or leaked. But combining them with a separate layer makes you exponentially safer. It’s like locking a door and needing a fingerprint to open it.
How I Use 2FA Now (And You Could Too)
Here’s my current system:
- Proton Pass as my password manager and 2FA tool (with 2FA enabled for it!)
- Encrypted backup of authentication codes (just in case)
- Device recovery plan in case of loss or theft
- Gradually removing SMS verification where possible
Is it perfect? No. But it’s much better than before — and I sleep better knowing that a stolen phone won’t automatically mean a stolen life.
Final Thoughts
Security isn’t something you notice when it works — only when it fails.
2FA lives in that in-between zone: not invisible enough to forget, not dramatic enough to fear. But it’s the layer that gives your password real power. And while it may slow you down by a few seconds, it could save you hours — or days — of regret.
Soon, I’ll share the full story of that phone theft, what was lost, what I learned, and how it changed how I relate to my digital self. But this week, let’s keep it simple: check your 2FA setup.