Protect · MFA/2FA

Turn On MFA/2FA Everywhere It Matters

Five minutes per account, and it's the single change most likely to stop someone else from ever getting into the accounts your income runs through.

By David O'Connor·Published August 8, 2026·Last verified August 8, 2026

In plain English

Multi-factor authentication (MFA), often called two-factor authentication (2FA), means logging in requires your password plus something else: a code from an app, a tap on your phone, or a physical security key. If someone steals or guesses your password, they still can't get in without that second thing, which they almost never have. Somewhere out there, a hacker is glaring at their screen, defeated by your phone. CISA's own guidance puts it simply: any MFA is better than no MFA, and it stops the overwhelming majority of automated account-takeover attempts cold.

Why this matters for every way to earn on this site

Every one of the 14 ways to earn covered here runs through at least one account that MFA can protect: an AdSense or YouTube login tied to years of ad revenue, an Etsy or Shopify admin panel connected to a bank account, a Google Ads or Workspace reseller login with client billing attached, even a Vinted or marketplace account holding an active wallet balance. The accounts with the most to lose (AdSense websites, YouTube, Etsy, Shopify) are exactly the ones worth starting with today.

The three types of MFA, weakest to strongest

SMS text codes

A code sent by text message. Better than nothing, but vulnerable to SIM swapping: a scammer convincing your mobile carrier to move your number to their SIM card, which then lets them receive your codes directly. Still, CISA is explicit that any MFA beats none, so SMS is a reasonable starting point if it's the only option a platform offers.

Authenticator apps

An app (Google Authenticator, Microsoft Authenticator, and similar) generates a fresh code every 30 seconds, tied to the device itself rather than your phone number. This sidesteps SIM swapping entirely and is free, fast to set up, and supported by essentially every platform covered on this site.

Hardware keys and passkeys

A physical security key (like a YubiKey) or a passkey stored on your device, using the FIDO/WebAuthn standard. CISA specifically calls this "phishing-resistant" MFA, because the key checks that it's talking to the real site, even a perfect fake login page can't trick it into approving. It's currently the strongest option, and increasingly supported by major platforms for free.

How to actually turn it on

  1. Start with your email account

    Whichever inbox receives password reset links for everything else is the single most important account to protect first. It's the master key to nearly everything downstream.

  2. Move to the accounts tied directly to income

    AdSense, YouTube/Google, Etsy, Shopify, Stripe or PayPal, and any marketplace or social commerce account. Each has MFA available in its security settings, usually under a name like "2-Step Verification" or "Two-Factor Authentication."

  3. Pick an authenticator app over SMS where you have the choice

    It takes the same amount of time to set up and closes the SIM-swapping gap for free.

  4. Generate and safely store backup codes

    Every major platform offers one-time backup codes for when you don't have your phone or key. Save them somewhere other than the same phone, like a password manager or printed and stored securely.

  5. Repeat for every other account that touches the business

    Domain registrar, hosting provider, and any freelance client portals are easy to forget, but a compromised domain or hosting account can take down an entire content site instantly.

What happens if you skip this

The realistic version, not the scary one: a password gets exposed somewhere (a breach at an unrelated company, a phishing email, a reused password cracked elsewhere) and without MFA, that's the whole story. Whoever has it logs straight in. From there it's usually one of a few outcomes: an AdSense or YouTube account gets its payout details quietly changed, a Shopify or Etsy shop has its bank details redirected before a payout lands somewhere else, or a YouTube channel with years of videos gets held for ransom or sold outright. Recovery is possible but slow, and platforms increasingly ask "did you have MFA enabled?" as one of the first questions: a "no" makes the recovery conversation considerably harder.

Questions people ask about this

Is MFA/2FA the same as a password reset code?

No. A password reset code is a one-time way back in when you're locked out. MFA is a second check required every time (or every new device), on top of your existing password, specifically so a stolen password alone isn't enough to log in.

Which type of MFA is actually the strongest?

In rising order of protection: SMS text codes (weakest, vulnerable to SIM swapping), authenticator apps (much stronger), and hardware security keys or passkeys using the FIDO/WebAuthn standard (currently the strongest, phishing-resistant option CISA recommends working toward).

What if I lose my phone with the authenticator app on it?

This is exactly what backup codes are for. Generate and store them somewhere safe (not just on the same phone) when you first set up MFA, before you need them.

Does MFA slow down logging in every single time?

Most platforms let you mark a personal device as trusted, so you're only prompted again after a password change, a new device, or a long gap, not every single login.

Sources & further reading

This guide is based on official government cybersecurity guidance, current as of the last-verified date above.

Jargon used on this page

SIM swapping
A scam where an attacker convinces a mobile carrier to transfer a victim's phone number to a SIM card the attacker controls, letting them intercept SMS-based MFA codes.
Authenticator app
An app that generates time-limited login codes on your device, independent of your phone number, used as a stronger form of MFA than SMS.
Passkey
A phishing-resistant sign-in credential stored on a device (or synced across devices) that replaces a password entirely, built on the FIDO/WebAuthn standard.
Backup codes
One-time-use codes generated when MFA is set up, used to regain access if the usual second factor (phone, key) is unavailable.

Next: How to Avoid Scams When Trying to Make Money Online →  |  ← Back to Protect

This page is general education, not a guarantee against account compromise. Platform-specific MFA options and setup steps change over time. Always confirm current details on the official platform page before relying on this guide. This site is not affiliated with, endorsed by, or sponsored by CISA, NIST, or any platform named on this site.