The Conversation That Made Me Rethink Everything
I want to tell you about the moment I almost gave up on getting my family to use multifactor authentication.
It was a Sunday evening in October. The kids were in bed. Emily and I were sitting on the couch, and I was going through my "let's make our accounts more secure" checklist. I'd just set up 2FA on my own email account and I was feeling good about it.
I turned to Emily and said, "Hey, I want to set up two-factor authentication on your email account. It'll only take a few minutes."
She looked at me. Then she said something I wasn't ready for:
"Is this going to make logging in harder for me?"
I started explaining how it worked—the authenticator app, the codes, how it was more secure. But as I talked, I saw her eyes glaze over. This wasn't a technical problem I was explaining. This was a friction problem I was introducing into her daily life. And she knew it.
That's when I realized my mistake.
I had been recommending 2FA to families for months. But I was explaining it to Emily like I was giving a presentation to security professionals. I was leading with "threat models" and "authentication factors" instead of the one question that matters to normal people:
"What does this mean for me, and is it worth the effort?"
Why 2FA Matters for Families
Before I tell you how to set it up without causing chaos, let me explain why it matters.
Here's the reality: passwords get stolen. It doesn't matter how good your password is. If a site gets breached, your password can end up online. And if you reuse passwords, the problem compounds—one breach gives an attacker access to multiple accounts.
Multifactor authentication is the backup plan. It's the second lock on the door.
Even if someone has your password, they can't get in without the second factor. And for families, this is critical. The attackers are opportunistic—they're looking for the weakest entry point. A compromised email account can lead to resetting other passwords, accessing financial accounts, or impersonating family members.
The short version: For about 60 seconds of setup per account, you dramatically reduce the risk of a serious security incident. And I'll show you how to make that as painless as possible.

The Three Approaches: How Families Actually Do This
I've learned from experience that there are three ways families approach 2FA. Each works for different households.
Option 1: The "Everything" Approach
What this is: Set up 2FA on every single account that offers it. Banking, email, social media, streaming, shopping—everything.
The upside: Maximized security. The baseline is full coverage.
The downside: The most friction. Not all accounts offer 2FA in the same way. Some use SMS, some use authenticator apps, some use hardware keys. Keeping track of all of this can be overwhelming—especially for families with children and shared accounts.
Who this is best for: Families with good security habits and a willingness to manage complexity. I recommend this only after the basics are working consistently.
Option 2: The "High-Value" Approach
What this is: Focus on the accounts that matter most. The accounts that would cause the most damage if compromised.
The priority list:
Priority | Account Type | Why It Matters |
|---|---|---|
Highest | If someone gets into your email, they can reset all other passwords | |
Highest | Banking / Financial | Direct access to money |
Highest | Password Manager | It holds everything else |
High | Primary Social Media | Impersonation and identity theft |
High | Primary Shopping Account | Payment methods stored |
Medium | Health accounts | Sensitive personal information |
Medium | Utility accounts | Billing information and address |
The upside: Much less friction. You focus on the accounts where the consequences are highest.
The downside: You still need to decide which accounts are high-value. Some security risks remain if you choose not to cover certain accounts. But the reduction in risk is significant—more than enough for most families.
Who this is best for: Most families. This is the baseline I recommend. It hits the balance between security and usability.
Option 3: The "Just Email" Approach
What this is: Only enable 2FA on your primary email account.
The upside: Minimum friction. It protects the single most critical account.
The downside: All other accounts remain vulnerable. If another account is compromised, it could lead to a larger incident. This is better than nothing, but it's not a full solution.
Who this is best for: Families that are just starting out. If you only do one thing, this is it.
The Right Way to Set Up 2FA (The One That Won't Annoy Your Family)
I've learned a few things about making 2FA work for families—things I wish I'd known before I started.
1. Use an Authenticator App, Not SMS
Here's the simple rule: Use an authenticator app when you can. SMS is okay when you can't, but it's less secure.
Why I recommend an authenticator app:
More secure. SMS messages can be intercepted or redirected.
Less reliance on the phone network. No "can't receive a text because the tower is down."
Better for families. If your child is using a phone and you manage accounts through it, authenticator apps work across devices.
No need for every person to have a phone number. Use the same app on a shared device.
Which authenticator app to use:
App | Platform | Notes |
|---|---|---|
Google Authenticator | iOS, Android | Simple, works, but no backup |
Microsoft Authenticator | iOS, Android | Good, supports backup |
Authy | iOS, Android, Desktop | Best for families—supports multi-device sync |
Bitwarden Authenticator | iOS, Android, Desktop | Integrated with password manager (if you use Bitwarden) |
Authy is my recommendation for families. Why? It syncs across devices, and it has a built-in backup. If someone loses their phone, you can still access the codes. Emily found it easier to use than any other app—especially because we could set it up once and use the same accounts across our devices.
2. Backup Codes Are Not Optional—They're Insurance
I cannot emphasize this enough: write down the backup codes and keep them somewhere safe. This is the one step most people skip, and it's the one that leads to the most frustration.
What backup codes are: One-time codes that bypass 2FA. You get them when you set up 2FA on an account. They allow you to regain access if you lose your device.
The safe way to store them:
A physical copy somewhere safe—in a drawer, a safe, or with other important documents
Not stored digitally in a place where they could be stolen if your account is compromised
A separate copy in a trusted location (like with a family member)
The one time I didn't do this: I learned the hard way when I had to reset a password manager account. I'd set up 2FA and managed the codes, but I didn't have a backup. I had to go through a long verification process with the company's support team. It was avoidable, and I now write down all backup codes.

3. Shared Accounts Are the Family Friction Point
Here's the challenge: Families share accounts. Streaming services, utilities, school accounts, and shared shopping logins. And 2FA introduces friction when you have to manage authentication across multiple people.
Solutions:
Share the authenticator app: Use Authy on a shared device that everyone can access. This works well for streaming accounts.
Use a password manager's shared vault: Some password managers allow you to store 2FA codes in the shared vault. This is a great option if your password manager supports it.
Use SMS as a fallback: For shared accounts, set up 2FA using one family member's phone number. This isn't the most secure option, but it's better than not having 2FA at all.
The approach I use for our family:
Email accounts: Individual 2FA (authenticator app) for each person
Shared accounts: Use the family password manager's shared vault, with 2FA stored in the vault
Kid accounts: Managed by me, with recovery options set up in case they need to reset anything
Utility accounts: Shared access through our authenticator app on a separate device
4. Make It a Team Effort
Here's what actually works: Set it up together. Don't just turn on 2FA and hand it off.
The partnership approach for our household:
Dave sets up the account and configures the authenticator
Emily verifies it works on her phone
Dave shows Emily how the backup codes work
They agree on a plan for what happens if someone gets locked out
They write down the recovery options and put them in a safe place
When we approach it this way, the friction is managed together—and everyone understands the process. Emily can now do it herself on accounts that matter to her.
5. Use Hardware Keys for High-Value Accounts
What they are: Physical devices (like YubiKeys) that plug into a USB port or use NFC. They provide the strongest authentication factor.
When I recommend them:
For primary email accounts (especially for parents)
For password manager access
For banking and financial accounts
When someone in the family is particularly high-risk
Why they're good: They can't be stolen remotely. They're physical. They're the strongest 2FA option available.
Why they're sometimes overkill for families: They cost money and you need a backup key in case you lose one. For most families, an authenticator app is enough.
The Specific 2FA Setup I Use for Our Family
I've spent time thinking through how our family handles 2FA, and I've learned that the right approach depends on your family's needs. Here's what we do—it might give you a starting point.
Account Type | Method | Notes |
|---|---|---|
Dave's Email | Authenticator app + Hardware key | Primary account |
Emily's Email | Authenticator app | She uses the same app on her phone |
Family Shared Accounts | Password manager's shared vault + shared authenticator app | Accounts that multiple people use |
Ella's School Account | Parent-managed with backup codes | I manage it, backup stored in the family safe |
Banking | Authenticator app | Both of us have access through the shared app |
Password Manager | Authenticator app + Hardware key | Additional security for the password manager |
The guiding principle: Keep it simple enough that everyone can follow it, but secure enough that the critical accounts are well-protected.
What About Kids and 2FA?
If your child has accounts, 2FA can be tricky. Many accounts don't allow 2FA for children, or it's not well-supported.
What I recommend for child accounts:
Use a managed account: Set up the account yourself and manage the 2FA from your own phone.
Use backup codes: Write down the backup codes and store them with the family's important documents.
Use a recovery email: Set up a recovery email address that's also protected by 2FA.
Don't use SMS if possible: If you can avoid SMS for the child's account, do it.
For example: When we set up Ella's school Chromebook account, I kept the authentication in my own authenticator app. I didn't try to have her manage it. That way, if something happens, I can assist without having to go through a recovery process.
The Five-Minute Setup
Here's a quick, realistic setup that takes about five minutes for the most important accounts:
Step 1: Pick One Account
Start with the account that matters most for you. For most families, this is email. Your email account can be used to reset passwords for most other accounts, so it's the highest priority.
Step 2: Choose Your Method
If the account supports authenticator apps, use one. Set it up on your phone. If the account only supports SMS or a security key, use that option instead. The main goal is to have some second layer, not to use a specific method.
Step 3: Enable It
Follow the prompts. At the end of the process, you'll get backup codes.
The most important step: Write down the backup codes. Put them somewhere safe.
Step 4: Check It Works
Log out and log back in with the 2FA method you just set up. If you can access the account, you're done.
Step 5: Do It Again
Repeat for your second high-value account (often a password manager or primary social media). If you have a second account, the process is easier the second time.
Step 6: Set a Reminder
Once you've done the first two, schedule a reminder to set up the next account. Don't try to do everything at once. Overlap is better than burnout.
I always tell myself: "Do one today, one tomorrow, and then the rest next week." It feels less overwhelming, and I actually follow through.
The Bottom Line
Multifactor authentication is the second lock on your door. You lock your front door at night. This is the same thing for your digital accounts.
If you only do one thing today, set up 2FA on your email. It's the account that matters most and it's the account that will be most frustrating to lose.
Next Week: We'll get into the specifics of what happens after a security incident occurs. I'll walk through the actual response steps you'd take if someone clicked the wrong link or a service was compromised.
Dave C. — Five minutes now beats five hours later.
No notes on this sheet yet.