http://www.iykpqm7jiradoeezzkhj7c4b33g4hbgfwelht2evxxeicbpjy44c7ead.onion/deeplinks/2016/12/12-days-2fa-how-enable-two-factor-authentication-your-online-accounts
That second factor can take several forms, including: A one-time verification code sent to you via SMS text message A time-based one-time password (TOTP) generated by a dedicated app, like Google Authenticator and Authy A download-able, print-able, hard-copy backup code A hardware token, like a Yubikey These generally rely on verifying something you have: your mobile phone, printed-out backup codes, another piece of hardware like a Yubikey, etc.