How does two-step verification work?
After you enable two-step verification, the system requires an extra password that you set in addition to the SMS or login code.
That means even if someone obtains your login code, they still cannot easily take over your account. It is also recommended to bind a recovery email.