Skip to content
Back to course

3. Two-factor authentication (2FA)

Welcome to Lesson 3! Even the strongest password can be stolen — through a data breach, a phishing link, or spyware on your phone. Two-factor authentication (2FA) is a second lock that makes your account almost impossible to break into even if a criminal already has your password. By the end of this lesson you will understand exactly how 2FA works, what types exist, and how to turn it on for the accounts that matter most.

Imagine you lock your front door with a key. Now imagine a pickpocket steals your key while you are on a minibus in Addis Ababa. They now have your key — and can open your house any time.

A password alone works the same way. It is one key. Anyone who gets that key can get in.

Passwords can be stolen in three main ways:

1. Data breaches — a website or app you use is hacked, and your password is leaked. This happens to big companies every year.

2. Phishing — you are tricked into typing your password into a fake login page.

3. Malware — a virus or spyware on your phone silently records your keystrokes.

Once a criminal has your password, your account is open to them — unless you have a second lock.

Two-factor authentication (2FA) is that second lock. It requires two separate proofs of identity before letting anyone in. A criminal with only your password fails at the second step and is locked out.

Security experts divide login proofs into three categories:

Something you KNOW

This is information stored in your memory — your password, PIN, or a secret question answer. It can be stolen if someone tricks you or hacks a database.

Something you HAVE

This is a physical object only you carry — your phone. When an app sends a 6-digit One-Time Password (OTP) to your SIM or a code generated by an authenticator app, the criminal must physically have your phone to get it.

Something you ARE

This is your body — your fingerprint, your face, your iris. Biometrics are very hard to copy and are built into most modern phones.

The most common 2FA combination on Ethiopian apps (TeleBirr, CBE Mobile, Gmail, Facebook) is:

Password (something you know) + SMS OTP (something you have)

Every time you log in from a new device, the app sends a 6-digit code to your registered phone number. You must type that code within a few minutes. A criminal in another city — or another country — who has your password but not your SIM card will be locked out.

Critical rule: your OTP is a secret, just like your password. Never read it aloud or share it with anyone — not with a person who calls claiming to be from TeleBirr, CBE, Ethio Telecom, or any bank. A real support agent will NEVER ask for your OTP. When a criminal is trying to break into your account, the app sends the OTP to your phone. The criminal then calls you urgently asking for it. If you read it out, they are in. Hang up immediately.

Not all 2FA methods are equally strong. Here they are from most common to most secure:

1. SMS One-Time Password (OTP) — most common in Ethiopia

The app texts a 6-digit code to your registered phone number. It is easy and widely supported. Its weakness: SIM-swap fraud (see below). Still, SMS 2FA is vastly better than no 2FA.

2. Authenticator app (TOTP) — stronger

Apps like Google Authenticator or Microsoft Authenticator generate a new 6-digit code every 30 seconds using a secret key stored on your device — no SMS needed. Even if a criminal intercepts your SMS, they cannot get this code. Recommended for Gmail, Facebook, and any account holding money.

3. Biometric unlock — very common on phones

Your phone uses your fingerprint or face to confirm it is really you. Most TeleBirr and banking apps in Ethiopia already require this when you open the app — it counts as a second factor combined with your PIN.

4. Hardware key — most secure, rare in Ethiopia

A small USB or NFC device (like a YubiKey) that you physically plug in or tap. This is used mainly by businesses and security professionals.

For most Ethiopians: start with SMS OTP. Then upgrade your most sensitive accounts (email, mobile money) to an authenticator app when you feel comfortable.

Turning on 2FA takes about two minutes per app. Here are step-by-step instructions for the four apps most Ethiopians use:

Gmail / Google Account

1. Open the Gmail app and tap your profile picture in the top-right corner.

2. Tap "Manage your Google Account."

3. Tap the "Security" tab.

4. Scroll to "How you sign in to Google" and tap "2-Step Verification."

5. Tap "Get started" and follow the prompts — enter your phone number to receive SMS codes, or choose an authenticator app.

Facebook

1. Open Facebook and tap the three horizontal lines (menu) in the top-right.

2. Scroll down to "Settings & Privacy" → "Settings."

3. Tap "Password and Security."

4. Tap "Two-factor authentication" and tap "Use two-factor authentication."

5. Choose SMS codes or an authentication app, then follow the steps.

Telegram

1. Open Telegram and tap the three horizontal lines in the top-left.

2. Go to "Settings" → "Privacy and Security."

3. Tap "Two-Step Verification."

4. Enter a strong password (this is your second factor for Telegram — not an SMS code but a password you choose).

5. Add your email as a recovery option.

TeleBirr

TeleBirr uses your Ethio Telecom SIM for OTP by design. To strengthen it:

1. Open TeleBirr and go to "My Account" → "Security Settings."

2. Make sure your registered phone number is up to date.

3. Set a strong 6-digit PIN that is not your birth year or a simple pattern.

4. Enable biometric login (fingerprint or face) if your phone supports it.

Save your backup codes! When you enable 2FA on Gmail or Facebook, the service gives you a set of one-time backup codes — usually 8 to 10 codes. These let you get back into your account if you lose your phone. Write them down on paper and keep them somewhere safe at home (not in the same bag as your phone). Without backup codes, losing your phone could lock you out of your own account permanently.

Scenario

Almaz received a text message with a 6-digit code. Seconds later her phone rang: the caller said he was from TeleBirr support and that he needed the code to "fix a problem" with her account. What should Almaz do?

Lesson recap: • 2FA adds a second lock to your account — a criminal with only your password cannot get in. • The three factor types are: something you know (password), something you have (your phone/OTP), and something you are (fingerprint/face). • The most common 2FA in Ethiopia is SMS OTP — a 6-digit code sent to your phone. Authenticator apps (Google Authenticator) are stronger. • Turn on 2FA today for Gmail, Facebook, Telegram, and TeleBirr — it takes about two minutes per app. • Your OTP is secret. No real company will ever call and ask for it. Hang up on anyone who does. • Save backup codes somewhere safe — they let you recover your account if you lose your phone. • SIM-swap fraud can bypass SMS OTP — protect yourself by setting a SIM lock PIN and upgrading to an authenticator app for your most sensitive accounts.

Check your understanding

1/7 · 80 XP

What is the main purpose of two-factor authentication (2FA)?