AGAccount Guard Open the partner account
Account Guard / Two-factor
Door 02

The second factor is only as good as the channel it uses

A second factor turns a stolen password into a stolen password plus a second problem. But not all second factors are equal, and the most common one — a code by text message — protects against the least and fails to the most popular modern attack. This page is about which channel to trust.

What a second factor actually does

A second factor is a second, different proof that the login is really you. It raises the cost of the two most common attacks at once: a stuffed or guessed password is no longer enough on its own, and a password captured by a fake login page is no longer enough either, because the attacker still lacks the factor.

What it does not do is protect an account that is already logged in. If a session is open, a second factor was never going to be asked for again — which is why the device and session list is a separate door, not a footnote.

SMS codes and the SIM swap

A code by text message is better than nothing and worse than it looks. The code travels over the phone network, and the phone network identifies you by your number — which can be moved. In a SIM swap, an attacker convinces the mobile provider to port your number to a SIM they control, and from that moment every code meant for you arrives on their device.

How a text-message code is defeated, step by step
recon
port request
number moves
code diverted
login approved

The swap rarely involves breaking into anything of yours. It involves convincing a person at the mobile provider, sometimes with details gathered from elsewhere. That is why a factor that does not travel over the phone network is the recommendation, and why SMS is best treated as a fallback rather than the goal.

Authenticator apps

An authenticator app generates codes locally from a shared secret, with no message crossing the phone network. A ported SIM does not receive them, so a SIM swap no longer opens the door. That single difference is why this is the sensible default second factor on an account that offers it.

Two caveats are worth knowing. The codes are still typed into a page, so a convincing fake can capture a code in real time — an app defends against a stolen password, not against a live phishing page. And the app's secret lives with your device: if you lose the device and have no recovery codes, you are in the recovery path rather than simply logging in.

Hardware keys and site-bound factors

A hardware security key is the strongest common factor because it proves possession of a physical object through a challenge that is bound to the real site. There is no code for a fake page to capture, because the key will not answer for a page at the wrong address — so this factor defeats phishing and SIM swap together.

The trade-off is convenience and availability: you must have the key with you, and losing it is a problem unless you hold a backup. Where an account supports this class of factor, it is the one worth setting up for the account itself; where it does not, an authenticator app is the practical best.

Recovery codes are part of the factor

Every second factor comes with recovery codes — one-time strings that let you back in when the device or key is gone. They are the spare key, and they are also the softest part of the whole setup, because a screenshot of them in the same inbox they protect is no protection at all.

01
Store them offline, not in the inbox

Paper in a drawer, or an encrypted vault that is not the account or email being protected.

02
Keep them out of chat and cloud photos

A backup that syncs wherever the account does is a copy an attacker can reach with the same access.

03
Regenerate after any scare

If you suspect a compromise, old recovery codes may already be held by someone else; issue a fresh set.

04
Understand they are single-use

Each code works once. Running them down without replacing the set is how people lock themselves out.

This page carries an affiliate link to gamdom.com/r/csgo2026. If you open an account through it we may earn a commission. It costs you nothing extra, it does not change what we write, and no operator, platform or security vendor pays for a position here. 18+ only. Gambling involves risk and can cause serious financial harm — including debt, damaged relationships and mental-health problems. Losing access to an account, or having one taken over, does not make staked money recoverable: funds already played and lost are gone, and no security control described here changes that. Never fund play with money you cannot afford to lose, never borrow to gamble, and never deposit more to recover a loss. Free, confidential support exists in most countries through national gambling-harm helplines.

Next

Harden the account before someone else tests it

If you want to see a live, age-gated account's own security settings for yourself, the partner link below opens one. Nothing you read here replaces what that account actually offers.

Open the partner account