Two-factor authentication (2FA) adds an extra layer of security by requiring a second, independent proof of identity beyond a password. This second step is usually something you have, like a code from an app or a hardware key, rather than something you know, like a password. This means that even if a password is stolen or guessed, an attacker still needs this second factor to gain access.
Authenticator apps, which generate rotating codes, are generally more secure than SMS-based codes because SMS can be intercepted through attacks like SIM-swapping. Most major email, banking, and social media services offer 2FA as an optional security setting, allowing users to protect their accounts with this extra safeguard.