Secure your Mozilla account with Two-Step Authentication

Mozilla Account Mozilla Account Laas bygewerk: 67% of users voted this helpful
Nog niemand het gehelp om dié artikel te vertaal nie. As u reeds weet hoe om vir SUMO te lokaliseer, begin nou te vertaal. Om eers te leer hoe om artikels vir SUMO te vertaal, begin gerus hier.

Two-step authentication, also known as two-factor authentication (2FA), adds an extra layer of security to your Mozilla account. Even if someone gets hold of your password, they won’t be able to access your account without a second factor of authentication. This second factor ensures that your account stays protected, even in the case of compromised credentials. By enabling 2FA, you greatly reduce the risk of unauthorized access, helping keep your personal data and browsing history safe.

How to set up two-step authentication

  1. Sign in to your Mozilla account and enable two-step authentication in the security section to enable this feature.
  2. Set up an authenticator app. Use a trusted app like Google Authenticator (Android, iOS & macOS) or Twilio Authy Authenticator (Android, iOS & macOS) to generate codes for signing in and be sure to download your backup authentication codes.

Recovery options for two-step authentication

If you lose access to your authenticator app or device, recovery methods ensure you can regain access to your account.

Recovery methods during 2FA setup

To enable two-step authentication (2FA) on your Mozilla account, you must set up at least one recovery method – either backup authentication codes or a recovery phone. If you do not complete setup of a recovery method, 2FA will not be enabled, even if you complete other steps.

Some users may be prompted to choose between backup codes and a recovery phone number when initially setting up 2FA. If you choose to set up a recovery phone, you will not automatically receive backup codes. However, you can add or switch recovery methods at any time through your account settings once 2FA is enabled.

Backup authentication codes

When you set up 2FA and choose backup codes as your recovery method, you’ll receive a set of 10-character backup authentication codes to save in a secure location. Each code can be used once to sign in to your account if you lose access to your authenticator app.

Note: These are not the same as account recovery keys (related to sync data recovery) or one-time codes sent by email or SMS.
  • How to access: You can view and download your backup authentication codes when you set up two-step authentication. If you lose them, you can generate a new set from your account settings.
  • Pro tip: Store these codes in a secure location like a password manager or a physical safe.

Recovery phone

This feature, initially available to users in the US and Canada, allows you to add a recovery phone number to your account. If you lose access to your authenticator app, you can request a one-time password (OTP) via SMS to regain access to your Mozilla account.

progressive rollout banner This feature is experimental and is being introduced to the Firefox user base through a progressive rollout. It may not yet be available to all users.

How to add a recovery phone

You can add a recovery phone either during initial two-step authentication (2FA) setup or afterward in your Mozilla account settings.

  • During initial 2FA setup
    If eligible, you will be prompted to choose between backup authentication codes and recovery phone during 2FA setup. Select Recovery phone and follow the steps to enter your phone number and verify it with a one-time password (OTP) sent by SMS.
  • After 2FA setup
    1. Go to the Security section of your Mozilla account settings.
    2. Under Two-step authentication, look for the Recovery phone option.
    3. Add your phone number and verify it by entering the OTP sent to your phone.
Note: If you don’t see the option for a recovery phone, it means the feature is not currently available for your account.
Important: Your recovery phone number should belong to you and be kept up to date to ensure you can regain access to your account.

Changing or adding recovery methods

After enabling 2FA, you can always add, remove, or switch between backup codes and recovery phone in your Mozilla account settings.

Comparing recovery methods for two-step authentication

FeatureBackup authentication codes (Safest)Recovery phone (Easiest)
AvailabilityGlobalCanada and USA only
UsageOne-time use per codeOne-time use per code, valid for 5 minutes
Ease of accessRequires access to pre-stored codes, risk of losing the codesConvenient if phone available, but requires active network connection
SecurityRisk if codes lost or stored in unsecured locationVulnerable to SIM swap attack

Understanding SIM swap risk

SIM swap attacks occur when a malicious actor convinces your mobile carrier to transfer your phone number to their SIM card. Once they have control of your phone number, they can intercept messages, including one-time passwords (OTPs), used for account recovery. This makes phone-based recovery methods more vulnerable than offline options like backup authentication codes.

To mitigate SIM swap risks, ensure your mobile carrier account is secured with a strong password and, if available, its own two-step authentication (2FA).

Most major cellular providers publish steps you can take to protect your devices on their help centers. You can find a few below:

Best practices for account security

By taking these steps, you’ll ensure your Mozilla account remains secure and protected from unauthorized access.

These fine people helped write this article:

Illustration of hands

Volunteer

Grow and share your expertise with others. Answer questions and improve our knowledge base.

Learn More