Turn on two factor authentication
Add a six digit code to your sign in, in about two minutes, using any authenticator app. The single most useful thing you can do for this account.
Why it matters more here than elsewhere
On most services, an attacker with your password steals something. Here, an attacker with your password can pause your vaults, and a paused vault never delivers. The danger is not that they read your message. It is that they quietly stop it from ever being sent, and nothing appears to be wrong.
Two factor authentication removes that risk almost entirely, and it takes two minutes.
What you need
An authenticator app on your phone. Any of them work: Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden, the code generator built into your password manager. We use standard TOTP, so there is nothing to install from us.
The steps
- Go to Security in your account.
- Choose Enable two factor authentication. A QR code appears.
- Scan it with your authenticator app. If scanning fails, the same secret is shown as text you can type in.
- Enter the six digit code the app shows, to prove it is working.
- Save your backup codes. They are shown once. Do not skip this.
From then on
Signing in asks for your password, then the current six digit code. Codes rotate every thirty seconds, and a code from the previous or next window is accepted too, so a clock that is slightly out will not lock you out.
Turning it off
Under Security, and it requires your password and a current code. That is deliberate: someone who has stolen a live session should not be able to strip the protection off the account.
If your phone clock is wrong
TOTP depends on the time. If codes are always rejected, turn on automatic time setting on the phone. This fixes it in nearly every case.
Still stuck?
The assistant has read every page in this help centre and answers in seconds. If it cannot help, a person will.