What is two-step verification or 2FA/MFA?
It is an important security measure that adds a second layer of protection to verify online accounts. It is the most reliable method of proving user identity and ensuring secure access to company accounts, social networks or an email address.
Find out how two-step verification works and how it protects your personal data and strengthens your digital security.
How does two-step verification or 2FA/MFA work?
It requires two forms of identification to verify that the person attempting to log in is a specific user and grant access to their account.
To do so, use two of the following three factors to verify your identity:
- Something you knowThis can be a PIN code, the answers to security questions and, of course, your password.
- Something you have: usually refers to a physical object, such as a credit card, a security token (a small hardware device) or an ID card. It can also refer to your phone, the possession of which can be verified by an SMS code or a dedicated application, such as Google Authenticator.
- Something you are: is biometric data and is usually fingerprint or facial recognition, such as Apple's Touch ID and Face ID.
When you log in to any of your online accounts, the basic level of identification will only ask for your password to log in: it is the first step in verifying your identity. Two-step verification requires a second step to grant you access to your account.
And that second step is explained above: something you know, something you have o something you areThe system will ask you, for example, for a one-time PIN code sent by SMS to verify your identity.

Why is two-step verification important?
Because it adds an additional level of security to the procedure for accessing an online account, as it requires the user to identify themselves in two ways to verify that they are who they say they are.

Without that second piece of information, hackers trying to break into your account, no matter how much they have your password, will not be able to get in.
Two-step verification is best described as a security measure that requires two types of authentication to access an account.
In MasterBase®, in addition to the traditional login with username and password (something the user knows), we have two second-step access alternatives (something the user has):
- Yubikey: a physical device (USB) that generates a different key each time access is requested.
- OTP Key: one-time password, generated by a third-party application.
Why should you use two-step verification?
Because it provides ironclad protection, even when the strongest passwords fail. Even if you create a strong password, there's still a chance it could be leaked. If you have your two-step verification set up, no one will be able to access your account, even if they know the password.
Passwords used to offer security, but hackers have been discovering innovative ways to compromise them. The ways to do so can be diverse, such as data leakage, Spyware (malicious software), Phishing or some hacking or scam on your social network accounts.
Therein lies the importance of two-step verification. If your password falls into the hands of a hacker, but you use this two-step verification method your account will still be safe. It is this second step that makes it a powerful security measure.
How to set up two-step verification
By means of a one-time password or a one-time password OTP (One-Time Password). It is a password valid only for one authentication. An OTP addresses a number of shortcomings associated with the traditional password, which is static. The most important of these is that, in contrast to static keys, one-time keys are not vulnerable to REPLAY attacks.
They also make the system more resistant to brute force attacks, since each time the one-time password is changed, attempts to break the previous password are useless and you have to start over. Because if, eventually, an intruder were to succeed in registering an OTP that is already used to log in to a service or to perform a transaction, he will not be able to abuse it, since it will no longer be valid.
What is required?
Before enabling or configuring OTP Key you must have an application that generates this type of keys, from a cell phone or other mobile device. For example:
- Google Authenticator
- Microsoft Authenticator
- 1Password
- LastPass
How do I enable OTP Key in MasterBase®?
Log in:

Once you enter the platform with the user and password of the account, you must go to the section where the user and account data are located, on the upper right hand side of the platform.

There you will have to display the user options and select Configure two-step verification.

You will have before your eyes:

This option is disabled by default
You will need to activate it to enable OTP Key login and follow the instructions:


To finish, just log out. On your next login, the platform will first ask for your usual credentials and then the second step of your identity verification.

If any issues arise in the process of setting up your two-step verification, please contact our MasterBase® support area.



