LearnlystLearnlyst
Two-Factor on Everything That Matters
Tech & Internet

Two-Factor on Everything That Matters

TOTP or passkey on every high-value account — because SMS is not a factor

1h 5m9 photographed stepsBeginner

You will turn on TOTP or passkey-based two-factor authentication on your email, bank, Apple/Google ID, domain registrar, and password manager. You will learn why SMS codes are the weakest link, store backup codes in a physical drawer, and build a recovery plan so a lost phone does not lock you out of your own life.

What you'll learn

  • TOTP is a rolling code only your app and the server share — not routable to a SIM swap
  • Passkeys eliminate phishing because they bind to the domain
  • Backup codes are the airbag — store them off-device
  • A recovery plan means a lost phone is annoying, not catastrophic

Inside this course

  • Why SMS is the weak linkA SIM swap takes a phone call. A TOTP secret stays on your hardware.
  • Enroll your high-value accountsEmail first — it is the recovery path for everything else.
  • Backup codes in a drawerDigital is convenient until the phone is in a lake.
  • Recovery planA lost phone, a stolen laptop, a house fire — one of these will happen.

Full step-by-step lessons with photos unlock with a subscription.

Two-Factor on Everything That Matters preview 1
Two-Factor on Everything That Matters preview 2
Two-Factor on Everything That Matters preview 3

Free preview

First steps from Why SMS is the weak link

See how every step looks — photo, checklist, and pro tips included.

SMS travels the phone network. TOTP never leaves your device.
01SMS routes through carriers who hand out SIM swaps

Your phone number is not yours. A carrier employee or a convincing caller can port it to a new SIM. The code arrives on a stranger's phone. This is not theory — it is how high-profile accounts get drained.

The fix: remove SMS wherever the service offers TOTP or passkey. Keep SMS only on legacy accounts that offer nothing else, and flag those for migration.

TOTP: a shared secret that never crosses the wire again
02TOTP: a shared secret that never crosses the wire again

When you scan the QR code, you save a secret. Every 30 seconds your app and the server independently compute the same six digits from that secret plus the clock. Nobody intercepts it because it never travels after setup.

If the service offers passkey (WebAuthn), prefer it — it is phishing-proof and device-bound. TOTP is the fallback for everything else.

Pro tip. Screenshot the QR only if you encrypt that screenshot in your vault. Otherwise it is a plaintext second factor in your camera roll.

Full library access

Unlock every course

Subscribe for $9/month or $79/year — every category, every guide.

View plans

Free tips from this course

Each tip has its own step photo — browse free, then unlock the full course.

More Tech & Internet tips →

More in Tech & Internet

Related courses with photographed steps — browse before you subscribe.

Unlock Two-Factor on Everything That Matters + the full library

$9/month · Cancel anytime · All courses included

Sign up to unlock