Two-factor authentication was supposed to make our lives online safer. Instead, it has turned logging into an account into a small administrative procedure.
Enter password.
Receive code.
Find phone.
Unlock phone.
Open authenticator.
Find code.
Enter code.
Code expires.
Request another code.
Receive code.
“Too many attempts. Try again later.”
The theory is simple enough. Enter your password, prove you have your phone, and you're in. Unfortunately, technology has never been particularly good at leaving simple things alone.
You enter the password you have used for years. The website accepts it, then calmly announces that another verification step is required before you can continue.
Fine. The phone comes out. It is unlocked. The authenticator app opens. The six-digit number is located and entered before the clock runs out.
Then the website rejects it because apparently those 30 seconds were an eternity in the security world.
So you request another code. This time the code arrives by text message, because apparently the first method was not sufficiently complicated.
You enter the new number. The website pauses. A loading circle appears. For several seconds, nothing happens.
Then comes the message nobody wants to see: “We couldn't verify your identity. Please try again.”
At this point, the computer has successfully established that you are probably the person who owns the account. It has also established that you are becoming increasingly annoyed.
There is also the wonderful concept of the trusted device. You have used the same laptop for three years, but suddenly the website has decided it no longer trusts it.
Why? Nobody knows. Perhaps the laptop looked suspicious this morning. Perhaps it crossed an invisible digital border while you were making coffee.
You then receive a notification asking whether you are trying to sign in. Of course you are. You are sitting at the computer trying to sign in.
You press “Yes”. The website thinks about it. The browser thinks about it. The phone thinks about it. Eventually, everyone agrees that you may continue.
This is particularly entertaining when the service already knows an extraordinary amount about you.
It knows your name, email address, phone number, IP address, device, browser, location and sometimes even the physical characteristics of your face.
Yet apparently none of that is enough to let you check your account without completing a digital obstacle course.
Security questions are another masterpiece. “What was the name of your first pet?” sounds reasonable until you remember that you answered it twelve years ago.
Did you type “Max”, “max”, “Maxy”, or perhaps the full name? Nobody remembers, because nobody expected to need the answer again.
Then there are backup codes. You are told to download ten emergency codes and store them somewhere safe.
So you print them, save them in a password manager, put them in a drawer and probably take a photograph of them, creating approximately four new security problems while solving one.
The real problem is not that two-factor authentication exists. It is that companies keep adding friction without explaining what problem each extra layer actually solves.
Strong authentication is important. Account takeovers are real, damaging and increasingly sophisticated. Nobody sensible is arguing that passwords alone are enough.
But security should not become a competition to see how many times a legitimate customer can be made to prove their identity.
There is a point where security stops feeling like protection and starts feeling like punishment for successfully remembering your password.
The industry also needs to remember that ordinary people do not experience authentication as a technical system. They experience it as an obstacle between themselves and something they need.
When that obstacle becomes sufficiently irritating, people find shortcuts. They reuse passwords, disable protections, keep recovery codes in obvious places or approve notifications without reading them.
That creates the great irony of modern authentication: a system designed to make people safer can encourage precisely the behaviour security professionals spend their careers telling people to avoid.
Perhaps the answer is not more authentication. Perhaps it is better authentication.
Use strong standards. Make trusted devices genuinely useful. Detect unusual behaviour intelligently. Give people clear recovery options. Stop treating every normal login as an international cybercrime investigation.
And for the love of technology, if the six-digit code expires in 30 seconds, do not make the login page take 25 seconds to load.
Two-factor authentication is not the enemy. Badly designed authentication is.
A security system should make it difficult for criminals to access your account without making it unnecessarily difficult for you to access your own.
Because if I have to prove who I am one more time just to read an email, I may eventually start demanding that the website prove who it is.