Para autenticar os logins, a rede social agora permite que os utilizadores usem uma aplicação de terceiros, como o Google Authenticator ou o Duo Security, tanto em computadores como em dispositivos móveis. A empresa também reformulou o recurso 2FA com um “fluxo de configuração simplificado e que orienta o utilizador durante o processo de configuração”.
“Two-factor authentication is an industry best practice for providing additional account security and we just made it easier to set up,” wrote Dickens.
As SMS são o segundo fator mais comum para 2FA, embora, devido à sua vulnerabilidade, os profissionais de segurança têm sido advertidos contra o uso de SMS para verificação de autenticidade. O Facebook fornece o 2FA baseado em SMS faz algum tempo e continuará a fazê-lo, mas o uso de outros meios, como um dispositivos de hardware ou uma aplicação para autenticação 2FA, é geralmente considerado mais seguro.
Veja abaixo como poderá usar esta camada de proteção no Facebook.
How to set up 2FA on your Facebook account
1) On your computer, log in to your Facebook account. You can click here for Settings, or click the drop down arrow at the top right of the page on the blue notification bar. It’s to the right of the question mark:
2) At the bottom of the menu, click “Settings.” On the next screen, hit “Security and Login” on the menu on the left:
3) Scroll down to Two-Factor Authentication.
4) As you can see in the image above, you now have three choices for 2FA: you can go old-school and use your passcode plus a code from your phone, review a list of devices where you won’t need to use a login code, or get into your apps with special passcodes instead of using your Facebook passcode or login codes.
5) Next, select whether you’d like to use your phone number or an authentication app to add an extra layer of security.
Mais aqui.

Pedro Tavares is a professional in the field of information security working as an Ethical Hacker/Pentester, Malware Researcher and also a Security Evangelist. He is also a founding member at CSIRT.UBI and Editor-in-Chief of the security computer blog seguranca-informatica.pt.
In recent years he has invested in the field of information security, exploring and analyzing a wide range of topics, such as pentesting (Kali Linux), malware, exploitation, hacking, IoT and security in Active Directory networks. He is also Freelance Writer (Infosec. Resources Institute and Cyber Defense Magazine) and developer of the 0xSI_f33d – a feed that compiles phishing and malware campaigns targeting Portuguese citizens.
Read more here.



