Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
Tips & Tricks 5 min read

Two-factor authentication - here’s why you should use it!

For many online service providers, two-factor authentication has now become the state-of-the-art login procedure. Instead of simply logging in with your password, you need an additional factor. This differs…

two-factor authentication via mobile phone

Two-factor authentication has now become the state-of-the-art login procedure for many online service providers. Instead of simply logging in with your password, you need an additional factor. This is completely different from the usual login process: it makes it virtually impossible for third parties to gain access to your accounts. These methods, which are primarily hardware-based, aim to significantly enhance your online security.

What is two-factor authentication?

Two-factor authentication makes logging in to online services more secure. Two different authentication models are used for this purpose. A common example is a password combined with an automatically generated code. This makes it almost impossible for cybercriminals to log into your accounts. This makes two-factor authentication an indirect complement to SSL certificates, as these also secure the website whilst protecting the user.

The basic principle involves authentication using different categories. First, you usually enter your password. You then need a separate piece of hardware or software. This transmits a temporary key which you can use to log in.

Important: Entering two passwords does not constitute true two-factor authentication. There is a risk here that third parties could also intercept the second password. Instead, this authentication method relies on factors from different areas. These, in turn, relate to the categories of knowledge, possession or biometrics.

Two of these factors are required for successful login. Providers can request them one after the other - for example, when logging in to a website - or all at once, as with the online ID function.

Do you have any further questions about two-factor authentication, or would you like to implement it for your online service? If so, please feel free to contact us at any time!

Why two-factor authentication is so important

Data breaches have, regrettably, become an everyday occurrence and still represent a huge security vulnerability and threat. Against the backdrop of increasing digitalisation, having a way to protect sensitive data is therefore all the more important. This is particularly true as online services become increasingly significant for users.

Enabling two-factor authentication reduces the risk of hackers gaining access to your data. After all, a password alone is not enough to log in - even if it falls into the wrong hands. This approach is more important today than ever, as the number of cyberattacks is constantly growing. At the same time, many of them go unnoticed, at least until the supposedly secure data can be found on the internet.

When it comes to web hosting, you should therefore not only check whether SSL certificates are available. You should also find out whether the authentication methods you require are in place, so that no third party can gain access to your data.

How two-factor authentication works

Two-factor authentication normally begins with your personal password. The system transmits these login details to check that they are correct. The difference compared to conventional systems is that entering the password alone is not sufficient.

  • If your password is correct, you will proceed to the second step of two-factor authentication. This additional security measure prevents unauthorised persons from accessing your data.
  • Many common two-step authentication systems use external systems for verification in the next stage. This is the case, for example, when you receive a verification code via text message and are required to enter it. Alternatively, two-step authentication may require a fingerprint, a smart card or a USB token.
  • If you are in possession of the second means of identity verification, you can complete the two-factor authentication. Otherwise, it is not possible to access and use the requested content.
Two-factor authentication: The most common systems

Two-factor authentication is only as secure as the second factor used in the login process. That is why there are various methods that online services use for two-factor authentication. Before you choose a provider, you should check the options available for multi-factor authentication.

  • Biometric systems: For this form of two-factor authentication, you first need your biometric data. The most common biometric features include fingerprints, facial recognition and retinal scans. As this information is not kept secret in two-factor authentication, liveness detection is necessary.
  • Cryptographic token: With this method, you send a request to the token. It stores a private cryptographic key and can only carry out two-factor authentication using this key. Software certificates are used for this purpose. They store your key so that you can use it online for your two-factor authentication.
  • TAN/OTP systems: You have probably been using the TAN system with your bank for some time. Previously, you would receive a paper list containing all the numbers. These lists have been replaced by TAN generators. This can be a physical generator or an authenticator app. Both generate event- or time-based one-time passwords. This also includes the mTAN and smsTAN methods.
Please never deactivate this!

Ensuring the necessary security for your online accounts isn’t always convenient. Instead of saving your password, you have to go through two-factor authentication. You benefit from these additional security measures particularly when it comes to online banking, online shopping and web hosting. The credentials stored here are tempting targets for cybercriminals, which makes multi-factor authentication all the more important.

More posts

All posts
Security solutions 4 min read

Out-of-date software versions: a greater risk than many realise

Digital security stands or falls on whether systems are kept up to date. Yet many companies underestimate just how great the risk really is when software remains out of date. It is not just a matter of a few version numbers or…