The 2FA Excuses I Used to Make, and Why I Stopped Making Them

Jay Kells
Sep 07, 2025By Jay Kells

The 2FA Excuses I Used to Make, and Why I Stopped Making Them

For years I knew two-factor authentication was something I should turn on, and for years I didn't do it on most of my accounts. Not because I didn't understand what it did or how it worked, but because I had a running list of reasons it could wait until later. None of those reasons were actually good ones, and looking back, I can see exactly why I kept reaching for them instead of just spending the two minutes it takes to switch it on.


It Takes Too Long


My biggest excuse was time. I told myself that unlocking an app to grab a six-digit code every time I logged into an account was going to be more hassle than it was worth, especially for accounts I use daily without thinking. What actually happened once I turned it on was completely different from what I'd pictured. Most services only ask for that second step occasionally, not on every single login, and remember the device you're using for weeks at a time. Even when it does ask, it adds maybe five seconds to the process. I'd genuinely spent more time arguing with myself about whether to turn it on than I've spent entering codes in the months since I actually did it.


My Password Is Already Strong Enough


This excuse felt more reasonable to me at the time than the others. I'd already moved to a password manager and had long, random, unique passwords on every important account, so I told myself the extra step of 2FA wasn't really necessary on top of that. What I hadn't accounted for was that a strong password only protects against someone guessing or cracking it directly. It does nothing at all if the password itself gets exposed somewhere I never expected, a data breach on a site I'd forgotten I even had an account with, a phishing page that caught me on a bad day, or malware quietly logging keystrokes on a device I trusted without question. Two-factor authentication is what still stops someone getting in even after the password itself has already leaked somewhere. I've written before about why my email account gets more protection than any other account I own, and turning on 2FA there specifically was the single step that mattered most, well beyond the password sitting underneath it.


I'll Turn It On Eventually


This was the excuse that did the most damage, because it let me put off a five-minute task indefinitely without ever quite admitting I was avoiding it. I told myself I'd get around to it properly once I had a free afternoon, once I'd researched the best authenticator app, once I'd worked out a backup plan for every account in case I lost my phone. None of that groundwork was actually necessary before starting. I could have turned on 2FA account by account, beginning with the one that mattered most, in about the time it takes to make a cup of tea. Waiting for the perfect, fully-planned moment to do it properly just meant I stayed unprotected the entire time I was waiting, which is exactly backwards from what I intended.


Nobody's Actually Targeting Me


I used to assume that account compromises were something that happened to other people, businesses, public figures, people with something obviously valuable attached to their name online. What changed my thinking was realising that most account takeovers aren't targeted at a specific person at all. They're automated. Someone runs a leaked password list against thousands of email addresses at once and simply sees what sticks, and it doesn't matter whether you're an interesting target or not, only whether your password happens to appear on that particular list. I don't need to be interesting to a scammer for this to matter to me. I just need to have an account, which every single one of us does, usually dozens of them.


What Actually Changed My Mind


The moment that finally got me moving wasn't a personal scare of my own, it was reading through account-compromise stories where the person had a strong, unique password and still lost access, because the attacker got in through a leaked credential dump or a hijacked session rather than by guessing anything at all. In every one of those stories, 2FA would have stopped the attack cold, right at the point where the stolen password alone should have been enough to get in. That's really what tipped it for me in the end. A strong password is the first lock on the door. Two-factor authentication is the second one that still holds even if someone else has gotten hold of a copy of the first key.

Brass house key on white marble with warm golden light and floating dust motes.


Once I actually sat down and did it properly, the whole process across every account I cared about took less than half an hour, nowhere near the mental hurdle I'd built it up to be in my head over all those months of putting it off. If you're already storing your passwords in a password manager, most of them will generate and store your 2FA codes too, which removes even the small remaining friction of switching between separate apps to log in. If you want the fuller version of what I've put in place across every account I own, I've pulled it together in a free Safety Toolkit, and the NCSC has clear guidance on setting up two-factor authentication properly if you want the fuller technical detail.