Two-Factor Authentication
Two-factor authentication is a second code at login on top of the password. For a miner it locks down the pool account and the payout address rather than the asic.
What two-factor authentication is
A password leaks in three ordinary ways: it repeats from another site, somebody guessed it, or a trojan saw it. A second factor breaks that scheme, because a one-time code is in no database of stolen passwords.
A code from an app is more reliable than a code over SMS. A number gets intercepted by swapping the SIM card, and that is a working scheme rather than a rarity. An app with one-time codes lives in the phone and is not tied to the number.
Backup codes are the thing that makes people lose access. They are issued once when you turn the feature on, and they belong apart from the phone, on paper preferably, not in a note to yourself and not as a screenshot in the gallery.
What a second factor does not do: it does not stop somebody already inside from changing the payout address. That is why pools have confirmation of an address change and a pause after it, and the habit of looking at the payout address once a week costs less than any protection.
Quick reference table
| What it is | a second code at login |
| More reliable | a code from an app |
| Weaker | a code over SMS |
| Backup codes | keep them apart from the phone |
| What it does not protect | the payout address from somebody already logged in |
What a miner should turn it on for
The pool account: the payout address sits there, and it is the first target.
The email the pool is tied to. Password recovery gets around everything else.
The exchange or the service the coins go to. Withdrawals there are worth limiting to a list of your own addresses.
Check the payout address with your eyes, not from memory. A swapped address often matches yours in the first and last characters, and that is exactly how they are picked.
An example
The pool password matched the password from an old forum, and the forum leaked. With a second factor turned on the login never happened, and it all ended with an email about a failed attempt. Without it this would have been a changed payout address and a month of work into somebody else's pocket.
Related terms
Where to go next on the site
Hardware
- ASIC Miner knowledge base
Numbers
Questions and answers
Is a code over SMS enough
Better than nothing, but weaker than an app: a number gets taken by swapping the SIM card.
What should you do if the phone is lost
Access gets restored with the backup codes. Without them all that is left is pool support and a long check, which is why the codes get written down as soon as you turn the feature on.
Will a second factor protect the asics themselves
No. Miners have a story of their own: their own web interface password, ports closed to the outside and a monitoring key that only reads.
How the terms connect
Every link in the chain is clickable. Orange marks where you are now.
Looking for an ASIC miner
The catalog holds 212 models. You can compare them by hashrate and by joules per terahash, then plug your own rate into the calculator and see what stays in your pocket.
Page written and checked by Denys Klimchuk. Updated .