Passwords can be guessed, reused, stolen in breaches or captured by phishing sites. Passkeys and two-step verification make those attacks much harder.
Prefer a passkey when available
A passkey uses cryptographic keys stored by your phone, computer or password manager. The private part does not leave your device, and the passkey only works for the genuine website or app that created it. This makes passkeys resistant to conventional phishing.
When an important account offers passkeys:
- Open the account’s security or sign-in settings.
- Choose Create a passkey or Add a passkey.
- Confirm using the device’s PIN, fingerprint or face recognition.
- Give the passkey a recognisable name if the service asks.
- Confirm that your other devices can access a synchronised passkey, or add another passkey separately.
Do not remove an existing sign-in method until you have verified that the passkey works and understand the recovery process.
Otherwise, enable two-step verification
If passkeys are unavailable, enable two-step verification—also called 2FA, 2SV or multi-factor authentication.
Prefer methods in this general order:
- A physical FIDO security key.
- An authenticator app that generates time-based codes.
- A prompt sent to an already trusted device.
- SMS or email codes.
Any additional factor is normally better than a password alone. SMS remains useful when stronger methods are unavailable, but phone numbers can be transferred or recovered by an attacker.
Save recovery information
Download the service’s recovery codes and store them separately from the device used for authentication. If you register physical security keys, add at least two and keep the spare somewhere secure.
Review recovery phone numbers and email addresses. A strong second factor can be bypassed if an attacker can exploit a weak recovery route.
Never approve an unexpected prompt
An attacker may repeatedly trigger sign-in prompts and hope you approve one. Deny any request you did not initiate, then change the account password and review recent activity.
Never read an authentication or recovery code to someone who contacts you.