Two-Factor Authentication
Complete guide to setting up 2FA on shookout.com — protect your account with an additional security level in authenticator app, SMS or backup codes
1What is 2FA
Definition
Two-Factor Authentication (2FA / Two-Factor Authentication) — this additional level protection account, which requires two method confirmation identity:
- that-the, that you you know: password
- that-the, that you have: phone or authenticator
How it works
when login in account:
- Enter email and password (how usually)
- System requests second factor
- Enter 6--digit code from app or SMS
- only after that receive access
Security: Even if who-the finds out your password — without access to phone or to the authenticator cannot log in!
Why you need 2FA
Protection from:
- Hacking password: brute-force, phishing, leaks bases data
- Interception of sessions: stolen cookies
- Unauthorized access: if who-the found out password
- Losses money: if seller account is hacked
Statistics:
- 99.9% of attacks are blocked with active 2FA
- Accounts without 2FA are hacked 100+ times more often
- In 2024 78% successful hackingin — accounts without 2FA
Important: if you seller on shookout.com — 2FA MANDATORY for protection your income!
2Methods 2FA
Available methods
Authenticator
app generates codes locally on device
- The most secure method
- works without internet
- Free
- Recommended
SMS
code goes in text message on phone
- Simple to use
- No apps required
- Available everywhere
- Can be paid
Backup codes
Oneone-time codes for expermanent access
- work always
- No devices required
- for recovery access
- Automatically generated
Methods comparison
Authenticator (recommended):
- Maximum security
- works offline
- Free
- codes change every 30 seconds
- Requires installation app
SMS:
- Simplicity use
- No additional apps
- Vulnerable to SIM-swap attacks
- Does not work without a signal
- May incur charges (roaming)
Backup codes:
- always work
- Not depend from devices
- Oneone-time (10 codes)
- May be lost
- only for recovery
Recommendation: Use app-authenticator how main method + save backup codes. SMS only how backup option.
3setting 2FA in app
Step 1: Set up the app-authenticator
Best app:
- Google Authenticator
- iOS: App Store
- Android: Google Play
- Free and simple
- Microsoft Authenticator
- iOS & Android
- Cloud backup
- Additional features
- Authy
- iOS, Android, Desktop
- Multi-device
- Cloud synchronization
- 1Passwords are case-sensitiveds are case-sensitived
- if already uses a password manager
- Paid subscription
- all in one location
Step 2: Enable 2FA on shookout.com
- Log into your account on shookout.com
- Go to Settings → Security
- Find section "Two-Factor Authentication"
- Click "Enable 2FA"
- Select "Authenticator app"
- Enter current password to confirm
Step 3: Scan QR-code
- On screen will appear QR-code
- Open app-authenticator on your phone
- Click "+" or "Add account"
- Select "Scan QR code"
- Point the camera at the QR code
- Account "shookout.com" will appear in the app
if not can scan:
- Click "Enter code manually" below the QR code
- Copy the secret key (for example:
JBSWY3DPEHPK3PXP) - In the app, select "Enter key manually"
- Paste key
- Name account: shookout.com
- Type: By time
Step 4: Enter verification code
- In the authenticator app, find shookout.com
- You will see 6--digit code (for example: 123 456)
- code updates every 30 seconds
- Enter this code on site shookout.com
- Click "Confirm"
ℹ️ Time: Make sure, that time on phone is synced automatically! Incorrect time = incorrect codes.
Step 5: Save backup codes in multiple secure locationsackup codes
- after successful settings will appear list from 10 codes
- each code — one-time, 8 characters
- Example:
A5F3-9K2L - Click "Download codes" (a .txt file will be saved)
- Or copy and save in a secure location:
- Manager passwords (1Passwords are case-sensitiveds are case-sensitived, Bitwarden)
- Encrypted note
- Print and store in a safe
CRITICAL: without backup codes and without phone you NOT WILL BE ABLE log in in account! Save their directly now!
Step 6: Done!
Now when each login system will be proh code from the authenticator app.
4setting 2FA in SMS
When use SMS
- No smartphone to install the app on
- how reserve method alongside the authenticator
- Temporary solution
setting SMS 2FA
- Settings → Security → 2FA
- Click "Enable 2FA"
- Select "SMS"
- Enter number phone in international format:
- +7 (Russia):
+79001234567 - +380 (Ukraine):
+380501234567 - +1 (USA):
+15551234567
- +7 (Russia):
- Click "Send code"
- Your phone will receive an SMS with a 6-digit code
- Enter code on the site
- Click "Confirm"
- Save backup codes in multiple secure locationsackup codes
Restrictions SMS
- Delay: SMS can go in 1-5 minutes
- Roaming: can not work for abroad
- SIM-swap: vulnerable to SIM swap attacks
- Cost: some carriers charge a fee
Tip: Use SMS as a backup method. Primary — authenticator app.
5Using 2FA on login
Standard login
- Go to on shookout.com
- Click "Log in"
- Enter email and password
- Click "Continue"
- Will open page input 2FA code
- Open app-authenticator
- Find shookout.com and look at code
- Enter 6--digit code on site
- Click "Confirm"
- you logged in!
Trusted device
To not enter code each times:
- when login check the checkbox "Remember this device on 30 days"
- 2FA will not be requested on this device for 30 days
- On new devices a code will always be required
Management trusted devices:
- Settings → Security → Devices
- You will see list all trusted devices
- You can delete any device
- when next login with it will be required code
Login with backup code
if no access to the authenticator:
- On the page input 2FA code click "Use backup code"
- Enter one of the saved codes
- Click "Confirm"
- Code will be used (no longer valid)
- You remaining 9 codes
Important: each backup code one-time! When will remain 2-3 code — generate new.
6Backup codes
that this
Backup codes are one-time login codes for when:
- You lost your phone with the authenticator
- SMS not working (no signal, abroad)
- Phone ran out of battery
- Phone was reset to factory settings
how get backup codes
when first setting 2FA:
- codes generated automatically
- Shown only once
- Mandatory save!
after settings:
- Settings → Security → 2FA
- Find "Backup codes"
- Click "Show codes"
- Enter password
- You will see a list of codes
Format codes
- 10 codes included
- Format:
XXXX-XXXX - Letters and digits
- Case is not important
how store backup codes
Correctly:
- Passwords are case-sensitiveds are case-sensitived manager (1Passwords are case-sensitiveds are case-sensitived, Bitwarden, LastPass)
- Encrypted file in cloud (Cryptomator + Dropbox)
- Print and store in a safe at home
- Write in a notebook in a secure location
Incorrectly:
- In an unprotected note on your phone
- In a plain text file on your computer
- In an email to yourself
- In cloud without encryption
- On screenshot in gallery
Usage backup code
- when login on page 2FA click "Use backup code"
- Enter code (with hyphen or without — not important)
- code will work only once
- after use code becomes invalid
Generate new codes
if used all codes or want update:
- Settings → Security → 2FA
- Click "Generate new backup codes"
- Confirm action
- old codes will become invalid
- Get 10 new codes
- Save their
Tip: Generate new codes times in 6-12 months for security.
72FA management
Adding second method
for added reliability you can enable two method simultaneously:
- Settings → Security → 2FA
- if already configured authenticator, click "Add method"
- Select "SMS"
- Configure SMS
- Now can select method when login
Changing the primary method
- Settings → Security → 2FA
- You will see list active methods
- Next to the method is a button "Set as primary"
- Click on the desired method
- it will become method by default when login
Deletion method
If you want to remove one of the methods:
- Settings → Security → 2FA
- Next to the method is a button "Delete autofill"
- Confirm deletion
- Method will be disabled
Warning: Cannot delete last method without complete disabling 2FA!
Complete disabling 2FA
if want disable two-factor authentication fully:
- Settings → Security → 2FA
- Click "Disable 2FA"
- Enter password
- Enter code 2FA (last times)
- Confirm disabling
- 2FA disabled
Not recommended: Disabling 2FA significantly reduces security account!
8Access recovery
if lost phone
Option 1: Use backup code
- On the page login select "Use backup code"
- Enter one of the saved codes
- Log into your account
- Immediately configure 2FA on the new device
- Generate new backup codes
Option 2: SMS (if configured)
- when login select "Receive code by SMS"
- code will come on linked number
- Enter code
- Log into your account
Option 3: Contact with support
- if no neither backup codes nor access to SMS
- On the page login click "Can't log in"
- Select "Issue with 2FA"
- Fill in form:
- Email account
- Last login date
- Recent purchases (if were)
- Photo document for verification identity
- Send request
- Support will respond within 24-48 hours
- after verification 2FA will be temporarily disabled
Important: Processwith recovery in support can take 2-7 days. Therefore MANDATORY save backup codes!
if changeor number phone
If SMS is linked to an old number:
- Log into your account (use authenticator or backup code)
- Settings → Security → 2FA
- Find method "SMS"
- Click "Change number"
- Enter new number
- Confirm in code on new number
If you reset your phone
after reset phone authenticator will is deleted:
- Log into your account using backup code
- Settings → Security → 2FA
- Delete autofill the old authenticator method
- Reconfigure (new QR code)
- Generate new backup codes
Tip: Use Authy or Microsoft Authenticator — they support cloud backup and not will be lost when phone!
9Best practices
Security 2FA
- Use app for up to SMS
- Save backup codes in multiple secure locationsackup codes in several locations
- Enable cloud backup in the authenticator (Authy, MS Authenticator)
- Regularly check trusted devices
- Update backup codes times in 6-12 months
- Don't share codes with no one, not even support
- Not store codes in plain text
- Not do screenshots QR-codes
Backup
Configure multiple methods:
- main: app-authenticator
- Backup: SMS on other number
- Emergency: backup codes in a safe
Where store backup codes:
- Main copy: manager passwords (1Passwords are case-sensitiveds are case-sensitived, Bitwarden)
- Backup copy: print and in safe/reliable to
- Emergency copy: with a trusted person (member family)
What to do BEFORE resetting your phone
- Log into all accounts with 2FA
- Temporarily disable 2FA or use authenticator with cloud backup
- Make sure, that backup codes saved
- after reset configure 2FA again
Regular verification
Once in 3 month:
- Check trusted devices list
- Delete old/unused
- Make sure, that backup codes available
- Test login with backup code
- Update codes if remaining <3
10Frequently asked questions
Is it required 2FA on shookout.com?
For regular users — no. For sellers — really recommended for protection income.
Can I use one authenticator for several accounts?
Yes! In one app you can add unlimitedpermanent number accounts. each will be a separate entry.
that do if code not perceived?
Check time on phone — automatic sync must be enabled. Incorrect time = wrong codesodes.
How many backup codes you can use?
All 10 codes, each one-time. When they run out — generate new.
Can I use 2FA on several devices?
Yes! Scan one QR-code on several devices. Or use Authy with synchronization.
that if lost backup codes?
if is access to account — go to and generate new. if no access — only in support.
Is cloud backup in the authenticator safe?
Yes, if you use a reliable password and enabled 2FA for the authenticator itself (Authy, MS Authenticator).
Is it necessary to enter code on each login?
No, if you check "Remember device" — code not will be required 30 days on this device.
Can I disable 2FA if forgot password?
No. First restore your password, then you can manage 2FA.
Support asked for a 2FA code — this normal?
no! Those are scammers. Real support NEVER asks for codes 2FA or passwords.
Protect your account directly now!
Setting up 2FA takes 5 minutes but protects you forever
Enable 2FA