# COVERT Protocol Action #3: Implement Multi-Factor Authentication whenever possible Page: https://stenobird.com/podcast/the-opsec-podcast-7427985/covert-protocol-action-3-implement-multi-factor-authentication-whenever-possible Text version: https://stenobird.com/podcast/the-opsec-podcast-7427985/covert-protocol-action-3-implement-multi-factor-authentication-whenever-possible.md Podcast: [The OPSEC Podcast](https://stenobird.com/podcast/the-opsec-podcast-7427985) Published: 2026-02-09T16:30:00+00:00 Episode link: https://opsecpodcast.com/ Audio file: https://sphinx.acast.com/p/open/s/68871c0a2a38d6f5cb5925b7/e/698a031ad2345f67c3fb5e0f/media.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/the-opsec-podcast-7427985/episodes/covert-protocol-action-3-implement-multi-factor-authentication-whenever-possible Duration seconds: 384 ## Resource Implement multi-factor authentication (MFA) on every account, using the strongest method available with a graduated approach: 1. Audit all important accounts (email, banking, cloud storage, social media, password manager) to check whether MFA is supported. 2. For each account, go to the security or login settings and enable MFA. Choose the strongest method the service supports. 3. If using an authenticator app or hardware key, save backup/recovery codes securely (in case you lose your phone or key). 4. For accounts using SMS/email 2FA consider upgrading to a stronger method when available, especially for sensitive accounts. 5. Test the MFA setup by logging out and logging back in to confirm that the second factor works as expected. Recommended Tools Authy: a widely used authenticator app that generates time-based codes for TOTP-based MFA. Proton Authenticator: privacy-focused app for generating MFA codes offline. YubiKey: a hardware security key providing FIDO2/WebAuthn authentication for the strongest protection. More At: https://opsecpodcast.com/ Hosted on Acast. See acast.com/privacy for more information. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/the-opsec-podcast-7427985/episodes/covert-protocol-action-3-implement-multi-factor-authentication-whenever-possible/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/the-opsec-podcast-7427985/covert-protocol-action-3-implement-multi-factor-authentication-whenever-possible.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.