Use passkeys and two-step verification

Add phishing-resistant sign-in methods where possible and strengthen accounts that still depend on passwords.

Difficulty
Beginner
Time
About 15 minutes
Platforms
Any

Passwords can be guessed, reused, stolen in breaches or captured by phishing sites. Passkeys and two-step verification make those attacks much harder.

Prefer a passkey when available

A passkey uses cryptographic keys stored by your phone, computer or password manager. The private part does not leave your device, and the passkey only works for the genuine website or app that created it. This makes passkeys resistant to conventional phishing.

When an important account offers passkeys:

  1. Open the account’s security or sign-in settings.
  2. Choose Create a passkey or Add a passkey.
  3. Confirm using the device’s PIN, fingerprint or face recognition.
  4. Give the passkey a recognisable name if the service asks.
  5. Confirm that your other devices can access a synchronised passkey, or add another passkey separately.

Do not remove an existing sign-in method until you have verified that the passkey works and understand the recovery process.

Otherwise, enable two-step verification

If passkeys are unavailable, enable two-step verification—also called 2FA, 2SV or multi-factor authentication.

Prefer methods in this general order:

  1. A physical FIDO security key.
  2. An authenticator app that generates time-based codes.
  3. A prompt sent to an already trusted device.
  4. SMS or email codes.

Any additional factor is normally better than a password alone. SMS remains useful when stronger methods are unavailable, but phone numbers can be transferred or recovered by an attacker.

Save recovery information

Download the service’s recovery codes and store them separately from the device used for authentication. If you register physical security keys, add at least two and keep the spare somewhere secure.

Review recovery phone numbers and email addresses. A strong second factor can be bypassed if an attacker can exploit a weak recovery route.

Never approve an unexpected prompt

An attacker may repeatedly trigger sign-in prompts and hope you approve one. Deny any request you did not initiate, then change the account password and review recent activity.

Never read an authentication or recovery code to someone who contacts you.

Sources and further reading

This page was last reviewed on 26 July 2026