Turn On MFA/2FA Everywhere It Matters
Five minutes per account, and it's the single change most likely to stop someone else from ever getting into the accounts your income runs through.
In plain English
Multi-factor authentication (MFA), often called two-factor authentication (2FA), means logging in requires your password plus something else: a code from an app, a tap on your phone, or a physical security key. If someone steals or guesses your password, they still can't get in without that second thing, which they almost never have. Somewhere out there, a hacker is glaring at their screen, defeated by your phone. CISA's own guidance puts it simply: any MFA is better than no MFA, and it stops the overwhelming majority of automated account-takeover attempts cold.
Why this matters for every way to earn on this site
Every one of the 14 ways to earn covered here runs through at least one account that MFA can protect: an AdSense or YouTube login tied to years of ad revenue, an Etsy or Shopify admin panel connected to a bank account, a Google Ads or Workspace reseller login with client billing attached, even a Vinted or marketplace account holding an active wallet balance. The accounts with the most to lose (AdSense websites, YouTube, Etsy, Shopify) are exactly the ones worth starting with today.
The three types of MFA, weakest to strongest
SMS text codes
A code sent by text message. Better than nothing, but vulnerable to SIM swapping: a scammer convincing your mobile carrier to move your number to their SIM card, which then lets them receive your codes directly. Still, CISA is explicit that any MFA beats none, so SMS is a reasonable starting point if it's the only option a platform offers.
Authenticator apps
An app (Google Authenticator, Microsoft Authenticator, and similar) generates a fresh code every 30 seconds, tied to the device itself rather than your phone number. This sidesteps SIM swapping entirely and is free, fast to set up, and supported by essentially every platform covered on this site.
Hardware keys and passkeys
A physical security key (like a YubiKey) or a passkey stored on your device, using the FIDO/WebAuthn standard. CISA specifically calls this "phishing-resistant" MFA, because the key checks that it's talking to the real site, even a perfect fake login page can't trick it into approving. It's currently the strongest option, and increasingly supported by major platforms for free.
How to actually turn it on
Start with your email account
Whichever inbox receives password reset links for everything else is the single most important account to protect first. It's the master key to nearly everything downstream.
Move to the accounts tied directly to income
AdSense, YouTube/Google, Etsy, Shopify, Stripe or PayPal, and any marketplace or social commerce account. Each has MFA available in its security settings, usually under a name like "2-Step Verification" or "Two-Factor Authentication."
Pick an authenticator app over SMS where you have the choice
It takes the same amount of time to set up and closes the SIM-swapping gap for free.
Generate and safely store backup codes
Every major platform offers one-time backup codes for when you don't have your phone or key. Save them somewhere other than the same phone, like a password manager or printed and stored securely.
Repeat for every other account that touches the business
Domain registrar, hosting provider, and any freelance client portals are easy to forget, but a compromised domain or hosting account can take down an entire content site instantly.
What happens if you skip this
The realistic version, not the scary one: a password gets exposed somewhere (a breach at an unrelated company, a phishing email, a reused password cracked elsewhere) and without MFA, that's the whole story. Whoever has it logs straight in. From there it's usually one of a few outcomes: an AdSense or YouTube account gets its payout details quietly changed, a Shopify or Etsy shop has its bank details redirected before a payout lands somewhere else, or a YouTube channel with years of videos gets held for ransom or sold outright. Recovery is possible but slow, and platforms increasingly ask "did you have MFA enabled?" as one of the first questions: a "no" makes the recovery conversation considerably harder.
Questions people ask about this
Is MFA/2FA the same as a password reset code?
No. A password reset code is a one-time way back in when you're locked out. MFA is a second check required every time (or every new device), on top of your existing password, specifically so a stolen password alone isn't enough to log in.
Which type of MFA is actually the strongest?
In rising order of protection: SMS text codes (weakest, vulnerable to SIM swapping), authenticator apps (much stronger), and hardware security keys or passkeys using the FIDO/WebAuthn standard (currently the strongest, phishing-resistant option CISA recommends working toward).
What if I lose my phone with the authenticator app on it?
This is exactly what backup codes are for. Generate and store them somewhere safe (not just on the same phone) when you first set up MFA, before you need them.
Does MFA slow down logging in every single time?
Most platforms let you mark a personal device as trusted, so you're only prompted again after a password change, a new device, or a long gap, not every single login.
Sources & further reading
This guide is based on official government cybersecurity guidance, current as of the last-verified date above.
- More Than a Password · CISAOfficial US government guidance on multi-factor authentication and phishing-resistant MFA.
- Multi-Factor Authentication · NISTOfficial NIST small-business cybersecurity guidance on MFA.
Jargon used on this page
- SIM swapping
- A scam where an attacker convinces a mobile carrier to transfer a victim's phone number to a SIM card the attacker controls, letting them intercept SMS-based MFA codes.
- Authenticator app
- An app that generates time-limited login codes on your device, independent of your phone number, used as a stronger form of MFA than SMS.
- Passkey
- A phishing-resistant sign-in credential stored on a device (or synced across devices) that replaces a password entirely, built on the FIDO/WebAuthn standard.
- Backup codes
- One-time-use codes generated when MFA is set up, used to regain access if the usual second factor (phone, key) is unavailable.
Support this guide
If this guide got you to actually turn MFA on, you can support OpenVaultStudio.com with a one-time donation via Stripe. It goes straight toward hosting and keeping these guides up to date.
Support This Guide →Next: How to Avoid Scams When Trying to Make Money Online → | ← Back to Protect