Two-Factor Authentication requires second verification (SMS code, app, hardware key) beyond password, becoming essential security practice after major breaches (2015+). Twitter/Gmail/banks mandated it, improving security despite user friction. SMS-based 2FA vulnerable to SIM swapping; authenticator apps (Authy, Google Authenticator) better; hardware keys (YubiKey) best but low adoption. Mandatory 2FA annoying but necessary in breach-filled world.
Sources: 2FA Adoption Rates, Security Breach Statistics