qvib.pro
RU

Accounts and 2FA

One password everywhere means one leak breaks everything. Two-factor auth plus a password manager shuts down 99% of account threats.

бесплатно любой

Updated: 02.07.2026

$ TOTP setup: Settings → Security → Two-factor authentication → "Authenticator …
Accounts and 2FA

Why it matters

Passwords leak in bulk from other people's hacked sites and end up in public dumps. If you use the same password everywhere, an attacker only needs one such leak — he'll try that login and password against your email, GitHub, bank and cloud (a credential stuffing attack). And email is the "key to every door": a password reset from there hands over everything else.

A real-world scenario. A password from a long-forgotten forum leaked and landed in a dump. A bot automatically tried it across hundreds of services and got into an email account that had no 2FA. From there: password resets on every other account, plus the domain and payment accounts stolen. All of it because of one reused password and no second factor.

What to do (step by step)

  1. Turn on 2FA everywhere, starting with email, banking, GitHub, cloud storage and your password manager. Factor priority: hardware key (FIDO2) > TOTP app > push; SMS only if nothing else is available.
TOTP setup: Settings → Security → Two-factor authentication →
"Authenticator app" → scan the QR code in Aegis/2FAS →
enter the 6-digit code → SAVE the backup codes offline.
  1. A unique, long password for every service — generate and store them in a password manager, and remember only one master password.
  2. Save your 2FA backup codes offline or in the manager — otherwise losing your phone means losing access.
  3. Check the domain in the address bar before typing a login — phishing fakes letters (gооgle with Cyrillic characters). A password manager won't autofill on a spoofed domain — that's protection in itself.
  4. Check your addresses against known breaches and change any exposed passwords:
haveibeenpwned.com → enter your email → if it appears in a breach → change the password there.

What NOT to do

  • Don't reuse a password and don't do the "password + 1" trick.
  • Don't enter 2FA codes on a page you opened from a link in an email or message.
  • Don't approve a login or push you didn't initiate (the MFA-fatigue attack — they spam pushes until you tap one).
  • Don't read one-time codes out to a "support agent" or "bank employee" — real support never asks for them.
  • Don't rely on SMS alone — a SIM can be hijacked (SIM swap).

Self-check

  • 2FA is on for email, banking, GitHub, cloud storage and the password manager.
  • The 2FA backup codes are saved offline.
  • Every password is unique and lives in the manager (no repeats).
  • My emails have been checked on haveibeenpwned and exposed passwords are changed.
  • I know that support never asks for codes or passwords.

Tools

Читать по-русски →