You should have two-factor authentication on every financial account

Two factor authorization is something I have on every important account in my life.

Some social media sites require it, as people try to steal those all the time, and almost all financial accounts now require it. If you happen to have one that doesn't, you need to set it up right now.

While some accounts do have protections, like $50 on unauthorized charges on a credit card, many don't have immediate solutions. If someone breaks into your checking account and drains it, you don't get the cash back immediately upon reporting the theft.

It can take time and that will cause downstream problems.

The takeaway: Turn on two factor authentication on your financial accounts.

What is two-factor authentication?

Two-factor authentication, often shortened to 2FA or TFA, is when you're required to provide another layer of authentication in addition to your password (also, a password manager like 1Password can help too!). There are three main categories of authentication – something you know, something you have, and something you are.

google-2-step-verification

If you use GMail, chances are you are familiar with how it works. When you try to log into your email, do you ever see the screen to the right? That's two factor authentication. They are confirming it's really you trying to access your account. That's 2FA.

At an ATM machine, your ATM card is something you have and your PIN is something you know. Adding a retina scan or fingerprint would be something you are. The “something you are” part, biometrics, is often left out because you can't change it easily if you have to. If the bank stores it and that information is stolen, you can't change something about you as easily as a password or an ATM card. 🙂

Why is this important? One factor authentication is less secure than two factor authentication because … well, two is more than one. 🙂

If you rely only on a username and password, you open yourself up to a lot of risk because that's all someone needs to get access to your account and wreck havoc on your finances.

With two factor authentication, in its most common form, you would get a text message with a PIN. When you log in, you have to provide that extra PIN to get access.

It's a minor inconvenience for you, it's a major inconvenience for someone looking to break into your account. They would need your phone too.

Is 2FA perfect? No – it's still possible to break into your account but it's made a little bit harder. A little bit harder means thieves might move onto the next account.

Check here to see if your financial institution offers it. Many will offer 2FA with a text message, phone call, email, or authenticator app. If your financial institution offers it, I recommend doing it.

And if you have the option, do not use text messages. Text messages are not encrypted or as secure as using an Authenticator app. Bloomberg discovered that a Swiss company got a million 2FA messages in June 2023 and while that alone isn't enough to cause problems, you can see how that's still not a good thing. I use the Google Authenticator app.

I went through this process years ago with Vanguard and the basic flow will be similar for any account.

Setting up Two-Factor Auth on Vanguard

Years ago, after confirming with twofactorauth.org and learning Vanguard offered 2FA, I set it up. Very easy.

vanguard-account-maintenance

To do it, log into your account and click on the My Accounts drop down in the top menu.

Then click on Security Code in the Security Profile section in the lower right.

(click to expand, but it's in the lower right)
(click to expand, but it's in the lower right)

You'll be prompted with a sign-up page followed by a Security Code Service Terms and Conditions page.

vanguard-establish-contact-phone-number

Next, you select your Phone Number and Contact Method (I chose Text).

vanguard-confirm-phone-number

You'll get a text with the six digit number and ten minutes to enter it before it expires.

vanguard-select-frequency

Finally, set the rules for when to use 2FA – your choices are only one new computers or all the time.

I chose only when Vanguard doesn't recognize my computer or device.

There's a big NOTE on there that will have an impact on us – this added security breaks financial aggregators like Mint and Yodlee and I assumed it would break Personal Capital. I just logged in and unless I'm mistaken, Personal Capital was still able to updated as normal. Even if it didn't, it would have been unfortunate but security trumps convenience.

This isn't a perfect solution, there never will be, but it'll be one more layer of security. If nothing else, it's an early warning system too since you'll start getting text messages for login attempts you didn't make!

Remember to “Number Lock” Your Phone Number

Now that you have two-factor authorization, it's important to secure your phone. Many people use their phone for 2FA and thieves know this – so they may try to steal your phone number by porting it without your permission.

Fortunately, there's a simple solution – Number Lock (that's what Verizon, my carrier, calls it). By locking your number, it cannot be ported without you “unlocking” it first.

Here is the Verizon's FAQ answer explaining how it works:

What is a Number Lock?
If a scammer gets your personal information, they could transfer your mobile number to another carrier. This may be referred to as an unauthorized port out. Then, they could get your calls and texts to take control of other accounts, like banking and social media.

You can set up a Number Lock for free to protect your mobile number from an unauthorized transfer. Once a lock is set up for a number, that number cannot be ported to another line/carrier unless you remove the lock. You can set up a Number Lock with the My Verizon website and app or by calling Customer Service at *611.

This isn't usually turned on by default, so you'll have to log into your account and turn it on.

Other Posts You May Enjoy:

Albert App Review: An All-in-One Banking and Investing App?

Many personal finance apps specialize in specific tasks like saving money, earning a high-interest rate, paying bills, and potentially earning spending rewards. Finding one platform offering both banking and investing accounts can be challenging. That's not the case with Albert. This Albert app review dives into the various features that can help improve your finances.

NerdWallet Budgeting App Review

NerdWallet offers a free budgeting app powered by Plaid, but is it any good? See what we think about their latest offering.

Barclays Bank Review: High Rates for Savings

Everyone wants a great interest rate on their savings. But along with a good return, it's important to do business with a bank that's accessible and trustworthy. In this review of Barclays US online bank, I'll cover the strengths and weaknesses, and present you with a few online banking alternatives to consider.

About Jim Wang

Jim Wang is a forty-something father of four who is a frequent contributor to Forbes and Vanguard's Blog. He has also been fortunate to have appeared in the New York Times, Baltimore Sun, Entrepreneur, and Marketplace Money.

Jim has a B.S. in Computer Science and Economics from Carnegie Mellon University, an M.S. in Information Technology - Software Engineering from Carnegie Mellon University, as well as a Masters in Business Administration from Johns Hopkins University. His approach to personal finance is that of an engineer, breaking down complex subjects into bite-sized easily understood concepts that you can use in your daily life.

One of his favorite tools (here's my treasure chest of tools, everything I use) is Empower Personal Dashboard, which enables him to manage his finances in just 15-minutes each month. They also offer financial planning, such as a Retirement Planning Tool that can tell you if you're on track to retire when you want. It's free.

>> Read more articles by Jim

Opinions expressed here are the author's alone, not those of any bank or financial institution. This content has not been reviewed, approved or otherwise endorsed by any of these entities.

See Jim on Instagram | Linkedin | TikTok

Subscribe
Notify of
guest

20 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Joe
9 years ago

Thanks for the tip. I have TFA on a few accounts, but not at Vanguard. That’s my biggest account so I’ll set it up today. Security is paramount. I really hope it doesn’t screw up Personal Capital.

9 years ago
Reply to  Jim Wang

Hi Jim,

Thanks for the post. Do you think using a financial aggregator that actively links your accounts puts your information at greater risk of being misused or falling into the wrong hands? I have not used one in the past, but was just looking into personal capital because of your post.

Reply to  Joe

Yodlee works with many 2FA accounts.

What a scary story–and a great take-away. Thanks for walking us through how to set this up in Vanguard.

9 years ago

Thanks for the reminder. I’ve been meaning to do this but wasn’t actually sure how to go through the process. I will set these up on my investment accounts today.

9 years ago

That sounds very scary! These days you should have two factor authentication for your email as well.

9 years ago

My credit card number just got stolen a couple days ago, makes me more weary of issues like this. Right now, my online accounts are protected with ridiculously long passwords, but i’ll have to look into 2FA. Thanks

9 years ago

I set this up on my of my financial accounts – several after hearing about Larry’s scare. I use long/complex passwords, which also helps, but isn’t infallible.

I also subscribe to identity theft protection. My belief is identity theft is a matter of when, not if. There have been too many data breaches for me to believe my information is safe. That would be naive.

9 years ago

For what it’s worth, the two-step verification on USAA is incompatible with Personal Capital. I’ve worked with tech support and everything, and they just won’t play nice together. But the 2-step works just fine with PC for Vanguard and Ally. Totally with you on this — better to go through an extra step each time for the added security!

Reply to  Jim Wang

FYI Fidelity I had no issue with Personal Capital. With Betterment I initially had an issue with them, but they were able to get it to work with Fidelity.

theskillets
7 years ago
Reply to  Our Next Life

The irony is that USAA is an investor in Personal Capital.

John D
7 years ago

Re: SECURITY… Here is my experience with Yodlee/Personal Capital over the last 14 months. My greatest concern is their apparent failure to protect my login credentials. In short: > On 2016-12-12, I removed my credit union from the Personal Capital system because failed attempts by Personal Capital/Yodlee caused me to be locked out of my credit union account. Yes, 14 months ago in 2016. > On 2016-12-15, Yodlee kept trying to access my credit union, I contacted Personal Capital and the logon attempts ceased. > On 2018-02-15, FOURTEEN MONTHS after I deleted the account from Personal Capital, Yodlee again attempted… Read more »

As Seen In:

20
0
Would love your thoughts, please comment.x
()
x