Skip to content
THE TECHLEEZ / INDIA-FIRST DIGITAL INTELLIGENCE Monday, 24 August 2026
The Signal AIUPISmartphonesStartupsStreamingTravel TechEsports
Online Tips

Two-Factor Authentication on Google, WhatsApp and Instagram

SMS is the weakest second factor and the one almost every Indian account relies on. The hierarchy that matters, where to change it on each service, and the backup codes everyone skips.

SMS is the weakest form of two-factor authentication, and it is the one almost every Indian account relies on. An attacker who obtains a duplicate SIM in your name receives every code sent to your number — which is not a theoretical risk here, it is a well-documented category of fraud.

Turning on stronger second factors takes about fifteen minutes across your main accounts. Here is where to do it and what to choose.

The Hierarchy, Strongest First

  1. Hardware security key — a physical device. Strongest available, and overkill for most people.
  2. Passkey — cryptographic, tied to your device biometrics. Increasingly the best practical option.
  3. Authenticator app — codes generated on your device, never transmitted. The right default.
  4. SMS OTP — better than nothing, and vulnerable to SIM swap.

The jump from SMS to an authenticator app is the one that matters. Everything above that is refinement.

Google

Start here, because your Google account is the recovery route for most of your other accounts. If it falls, everything else follows.

Go to myaccount.google.com → Security → 2-Step Verification.

  • Add an authenticator app as your primary second factor.
  • Generate backup codes — ten single-use codes. Print them or write them down somewhere physical. This is your escape hatch when a phone is lost.
  • Consider adding a passkey for passwordless sign-in.
  • Keep SMS as a fallback rather than the primary method.

While you are there, review the devices list and remove anything you no longer own. Our guide to recovering a Google account without the phone number explains why this setup matters so much.

WhatsApp

WhatsApp’s protection is different in kind, and widely misunderstood.

Go to Settings → Account → Two-step verification and set a six-digit PIN.

This PIN is required whenever your number is registered on WhatsApp on a new device. It means that even if someone controls your number and receives the registration SMS, they still cannot complete the takeover without the PIN.

Given how much of an Indian phone’s life runs through WhatsApp — and how effective account takeover is at defrauding your contacts — this is arguably the single highest-value five seconds in this article. Add a recovery email address at the same time, or a forgotten PIN locks you out for days.

Instagram

Settings → Accounts Centre → Password and security → Two-factor authentication.

Choose the authentication app option rather than SMS. Instagram accounts are targeted heavily for resale and for running scams against your followers, and recovery through the platform is notoriously slow — prevention is worth considerably more than the cure here.

Save the recovery codes it offers.

Banking and UPI

These mostly do not offer app-based 2FA in the way Google does; they use their own device binding, MPINs and SMS OTP.

What you can control: set a strong app lock or biometric on each banking app, never save UPI PINs anywhere, and keep the number registered with your bank private. Using a separate, unpublished number for banking is one of the more effective habits available, for the reasons set out in our guide to SIM swap fraud.

Which Authenticator App?

Google Authenticator, Microsoft Authenticator and Authy all work. The important consideration is not which one but what happens when you lose the phone.

Some sync codes to a cloud account; some do not. If yours does not, and you wipe the handset without exporting, you lose every code at once. Check which behaviour yours has, and if it offers cloud sync, decide deliberately whether you want it — sync is more convenient and slightly less private.

Whichever you choose, migrate it deliberately when you change phones, as covered in our guide to moving to a new phone without losing data.

Backup Codes: The Part Everyone Skips

Every service that offers 2FA also offers backup codes, and almost nobody saves them. They are the only reliable route back into an account when your phone is lost, stolen or bricked.

Print them. Keep them with your important documents, not in a note on the phone they are meant to rescue you from. Treat them like a spare house key.

A Fifteen-Minute Pass

Google first, with an authenticator app and saved backup codes. WhatsApp PIN and recovery email. Instagram on an authenticator. Then your email provider if it is not Google, and any account holding money.

Do the same for your parents. Older relatives are targeted disproportionately and are least likely to have moved off SMS. We publish practical Indian security guidance at Techleez com.

Where 2FA Does Not Save You

Worth being clear about the limits, because a false sense of completeness is its own risk.

Two-factor authentication protects the login. It does nothing against a scam where you willingly authorise a payment, approve a collect request, or read a code aloud to someone claiming to be from your bank. A great deal of Indian fraud never touches your password at all — it persuades you to act.

It also does not help if you approve the prompt without reading it. Push-based approvals train people to tap “Yes” reflexively, and attackers exploit exactly that by firing repeated requests until someone taps to make the buzzing stop. If a prompt arrives when you are not logging in, the answer is always no, followed by a password change.

And it does not protect an account whose recovery route is weak. An attacker who cannot pass your second factor may simply attack your recovery email or your phone number instead. Securing the front door while leaving the back door on SMS is a common and expensive mistake.

Check What Is Already Signed In

Once your second factors are in place, spend two minutes reviewing active sessions on each service. Google lists them under Security, WhatsApp under Linked Devices, and Instagram under login activity.

Look for devices and locations you do not recognise, and for linked-device entries on WhatsApp that you never authorised — WhatsApp Web sessions left open on a shared or office computer are a quiet and very common exposure. Sign out of everything you cannot account for, then change the password.

Frequently Asked Questions

Is SMS OTP safe enough?

It is better than nothing, but it is the weakest option and vulnerable to SIM swap. Move critical accounts to an authenticator app.

What does WhatsApp two-step verification actually do?

It sets a six-digit PIN required whenever your number is registered on a new device, so controlling your number alone is not enough to take over your account.

What happens if I lose the phone with my authenticator app?

You use your saved backup codes. If the app syncs to a cloud account, you can restore it there. Without either, recovery is slow and sometimes impossible.

Which authenticator app is best?

They are broadly equivalent. What matters is knowing whether yours syncs to the cloud, so you know what happens when the phone is gone.

Should I set up 2FA on banking apps?

Banking apps use their own device binding and MPINs rather than standard 2FA. Set a biometric app lock and keep your banking number private.

Where should I keep backup codes?

Printed or written down with your important documents — not in a note on the phone they exist to replace.

About the author

Fold Smith

Fold Smith is a technology journalist and the lead editor of The Techleez, an India-first publication that decodes technology, digital payments, streaming and online culture for everyday readers. From UPI and fintech explainers to OTT streaming guides, Android tips and online-safety checklists, he personally tests the apps, tools and services featured on the site before recommending them. His focus is practical, research-backed guidance that helps Indian readers make smarter digital decisions — spend less, stream better and stay safe online. When he is not writing, he is usually tracking NPCI circulars, first-day-first-show box office numbers, or the next big OTT premiere.

More from this author →