Two-factor authentication adds a second check beyond your password: a 6-digit, time-based code from an authenticator app on your phone, so someone who somehow learns your password still can't sign in without also having your device.
Setting it up
- Install an authenticator app if you don't have one already, Google Authenticator, Authy, and 1Password all work, this uses the standard TOTP protocol, not a proprietary one.
- Go to your Profile page → Security.
- Follow the prompts, you'll scan a QR code (or enter a setup key manually) into your authenticator app, then enter the 6-digit code it generates to confirm the setup actually worked.
What changes once it's on
Every time you sign in with your password, you'll be asked for a fresh 6-digit code from your app immediately afterward. Signing in with Google is a separate flow and isn't affected by this, 2FA specifically protects the password sign-in path.
Tip: Save your setup, or note down that you have 2FA enabled somewhere memorable — if you lose the device before setting up a backup, see "I lost access to my two-factor authentication device" for how to recover.