Facebook Protect and 2FA is about to become the rule for some accounts

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

Facebook is finally making 2-Factor Authentication (2FA) the rule for some of its most-at-risk accounts.

It’s a smart move, protecting venerable Facebook users, especially those who are looked to for responsible and accurate information - think journalists, politicians, celebrities, and you'll get the idea. 

Someone gaining access to any one of these accounts and masquerading as it could have wide-reaching, damaging effects, reported Wired.

Why I wonder has this taken so long?

Stories of people, in all stations of life, who’ve had critical accounts hacked are all too commonplace. I usually find out when someone sends me a separate email or text exclaiming, “Help! I’ve been hacked!” Worse yet is when they don’t know and I spot the bizarre activity on their Facebook account and send a private note through other channels: “Hey, I think your Facebook’s been hacked.’ 

2FA is a simple idea that few people adopt because they see it as annoying or overly complicated. Put simply, whenever you log into a system, you have to prove it’s really you through a secondary device or system, one that can give you a code to apply to that first system. 

Some 2FA systems use SMS texts to your phone (or a voice call), others use proprietary hardware that spits out unique, time-sensitive codes that also get entered into the original system.

For most people, the primary device handling 2FA is their smartphone. Most security system managers figure that if you have your phone with your SIM and unique phone number on it, that’s about as good as it needs to get for verification. Looked at another way, how likely is it that someone trying to use your email and maybe a password they found on the Dark Web to log into your Facebook will also have your phone in their hands?

Inside Facebook Protect: What's new?

The system in question, known as Facebook Protect, was designed originally as an opt-in for political figures. In addition to 2FA, there’s a Page publishing authentication system to ensure that nobody publishes offensive material on a candidate’s pages, and the requirement that Page managers use real names.

The new plan takes Facebook Protect further, with Facebook proactively identifying at-risk users or groups of users and targeting them to enroll in Facebook Protect. Personally, I’d like to see Facebook follow Google’s plan and require 2FA for all users.

It’s not a perfect system, and there are reports of phone scammers convincing unsuspecting service users (banks, cryptocurrency wallets, Venmo, PayPal, and other accounts that also use 2FA) to share the 2FA SMS codes. Still, it’s better than a single, poorly crafted password, or one that’s being passed around on the Dark Web like so much gossip.

Facebook’s plan, which sounds small and almost tentative, might still be a rude awakening for at-risk users who missed the memo and, after ignoring multiple prompts to enable 2FA, may find themselves locked out of their own accounts.

Facebook's Head of Security Policy Nathaniel Gleicher, however, told me via Twitter that the "Number of warnings will vary by country/context -- we're adjusting to make sure people have the time they need. So far, we've seen the overwhelming majority (90%+) enroll on time w/out trouble!"

Getting locked out of Facebook would not be a great situation. But it's definitely better than a hacker or prankster taking over and posting things in your account that no one wants to see.

Lance Ulanoff
Editor At Large

A 38-year industry veteran and award-winning journalist, Lance has covered technology since PCs were the size of suitcases and “on line” meant “waiting.” He’s a former Lifewire Editor-in-Chief, Mashable Editor-in-Chief, and, before that, Editor in Chief of PCMag.com and Senior Vice President of Content for Ziff Davis, Inc. He also wrote a popular, weekly tech column for Medium called The Upgrade.

Lance Ulanoff makes frequent appearances on national, international, and local news programs including Live with Kelly and Mark, the Today Show, Good Morning America, CNBC, CNN, and the BBC. 

Read more
Security padlock in circuit board, digital encryption concept
MFA alone won’t protect you in 2025: the new cybersecurity imperative
Representational image of a shrouded hacker.
Getting to grips with Adversary-in-the-Middle threats
An abstract image of a lock against a digital background, denoting cybersecurity.
Building a resilient workforce security strategy
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Microsoft is changing the way logins work: here’s what that means for you
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
digital key
Microsoft really wants users to ditch passwords and switch to passkeys
Latest in Security
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
Latest in News
Helly and Mark standing on an artificial hill surrounded by goats in Severance season 2 episode 3
New Apple teaser for Severance season 2 finale suggests we might finally find out what Lumon is doing with those goats, and I don't think it's anything good
Foldable iPhone
Apple’s first foldable iPhone could beat the Samsung Galaxy Z Fold 7 in one key way
Marvel Rivals
Marvel Rivals' next update will add two new hero skins for Iron Man and Spider-Man mains this week
Nvidia Isaac GROOT N1
“The age of generalist robotics is here" - Nvidia's latest GROOT AI model just took us another step closer to fully humanoid robots
Lego Pokemon
Pokemon and Lego announce the most electrifying collaboration of all time and I’m going to be first in line
Apple Watch app health
Apple Watch blood pressure monitoring tech revealed in patent