I finally did the thing I've been putting off since basically the Yahoo mess back in December. I sat down last Sunday night and turned on two-factor authentication for every account I actually care about. Not "meant to get around to it eventually" turned on. Actually turned on. It took about ninety minutes, one panicked moment where I thought I'd locked myself out of my own email, and a small pile of backup codes that are now folded up in a drawer where I will absolutely lose them by June.
Here's the thing that finally pushed me over the edge: I'd been using the same three password variations since roughly 2013, rotating them across sites like some kind of digital shell game, and after watching a billion Yahoo accounts get scooped up I realized the math on that was never going to work out in my favor forever. So, the actual how-to, since a few people asked after I mentioned this on Twitter.
Start with your email, not your bank
This is the part people get backwards. Your email is the recovery mechanism for almost everything else you own online, so it's the first domino. If someone gets into your Gmail they can reset your Amazon password, your Dropbox, your whatever, using the "forgot password" link. I use Gmail, and turning on 2-step verification there is buried in the account settings under Sign-in & Security — not hard to find, just not exactly front and center either.
Pick an authenticator app, not SMS, if you can help it
SMS-based codes are better than nothing, but they're not great — carriers have had SIM-swap problems for a while now, where someone convinces (or bribes, or social-engineers) a phone company employee to port your number to their device, and suddenly they're getting your codes instead of you. I went with Authy over Google Authenticator mainly because Authy backs up your codes to the cloud (encrypted) so a lost phone doesn't mean starting over from scratch on twelve different sites. Google Authenticator doesn't do that, which is its one real weakness as far as I'm concerned. Both are free, both take about ninety seconds per account to set up: scan a QR code, type in the six digits it generates, done.
Go down your list in order of how bad it would be
I did email first, then Dropbox, then my password manager itself (I use 1Password, and yes, protecting a password manager with 2FA feels a little like putting a lock on a lock, but that's the point), then Twitter, then the WordPress login for this actual blog, then Amazon. I skipped a bunch of low-stakes stuff, some forum I signed up for in 2012 and never posted on again isn't worth the friction.
One annoying wrinkle: some sites, Amazon included, still make you jump through extra hoops or don't support app-based codes at all and just fall back to text messages. Fine, better than nothing, but a little disappointing from a company that size in 2017.
Print the backup codes. Actually print them.
Every service gives you a set of one-time backup codes for when you lose your phone. I did the smart thing for once and printed mine out instead of leaving them as a screenshot buried in my camera roll, which is where good intentions like this usually go to die. They're in an envelope in my desk drawer now. My wife thinks this is a very "me" thing to do, and she's not wrong.
The almost-locked-out moment I mentioned: right after I turned on 2FA for Gmail, I closed the tab, restarted my laptop for an unrelated reason, and for about four minutes couldn't remember which authenticator entry was which because I'd renamed a couple of them and forgotten why. Small heart-attack, entirely self-inflicted, resolved by just reading the account names more carefully instead of panicking. Lesson: name your entries something obvious, not clever.
None of this makes you invincible. A determined enough person with enough resources can still get into most things if they really want to. But it raises the bar from "guess a password" to "steal a physical device or intercept a text message," and that's a meaningfully bigger ask for the kind of automated credential-stuffing that's been chewing through reused passwords for the last couple years. Ninety minutes on a Sunday night felt like a reasonable trade for that.