Free Training · Foundations

Two-Factor Authentication and Passkeys

A password can leak; a second factor means that isn't enough to get in. Learn which type of 2FA to use, where to turn it on first, and how passkeys are quietly making passwords obsolete.

Listen to this lesson

A password has one fatal weakness: if someone else learns it, they are you. Two-factor authentication removes that single point of failure by requiring a second, separate proof of identity when you log in. Even with your password in hand, an attacker is stopped at the door.

What "two factors" really means

The idea is to combine two different kinds of proof: something you know (your password) and something you have (your phone or a security key). An attacker on the other side of the world might steal what you know, but they don't have what you hold. That combination is what makes 2FA so effective against the automated, password-based attacks that cause most break-ins.

The types of 2FA, from good to best

  • Text-message (SMS) codes — okay. Better than nothing, and fine for low-stakes accounts. The weakness is that determined attackers can hijack your phone number ("SIM swapping"), so don't rely on it for your most important logins.
  • Authenticator app codes — better. An app on your phone generates a rotating 6-digit code. Nothing is sent over the network, so there's no number to hijack. This is the sweet spot for most people on most accounts.
  • Security keys and passkeys — best. A physical key or a passkey stored on your device proves it's really you and is essentially immune to phishing, because there's no code to trick out of you.

Where to turn it on first

You don't need 2FA on every account, and trying to do them all at once is how people give up. Work down this list in order:

  1. Your primary email — it can reset every other account, so protect it first.
  2. Banking and payment apps — anything with direct access to money.
  3. Your password manager — the vault holding everything else.
  4. Major shopping and social accounts — anywhere a takeover would be costly or embarrassing.

Look in each account's security or login settings for "two-factor," "two-step," or "2FA." When offered a choice, pick an authenticator app or a passkey over text messages.

Do this now

Turn on an authenticator-app second factor for your primary email account. It's the highest-value fifteen minutes in this entire course — that one account protects all the others.

Passkeys: the beginning of the end for passwords

A passkey replaces the password entirely. Instead of typing a secret, you approve the login with your fingerprint, face, or device PIN — the same way you unlock your phone. Behind the scenes your device proves who you are using cryptography, and there's no password to leak, guess, or phish.

Passkeys are both easier and safer, which is a rare combination. More sites support them every month, often labeled "sign in with a passkey." When a service you use offers one, take it — especially for email and financial accounts. It's the clearest example of security getting simpler, not harder.

Keep a backup method

Whatever you turn on, set up a recovery option too: save the backup codes the site gives you, or register a second device. That way a lost or replaced phone locks out attackers without locking out you. Store those backup codes in your password manager.

Clearing up the common confusions

Two-factor authentication trips people up in a few predictable ways. A little clarity makes it painless.

  • Codes are single-use and time-limited. An authenticator code changes every thirty seconds and works once, which is exactly why intercepting one is nearly useless to an attacker.
  • You won't be prompted constantly. Most services let you trust a device you use regularly, so you only face the second step on new or suspicious logins.
  • Never share a code — ever. A real company will never phone and ask you to read one back. Anyone who does is trying to log in as you at that exact moment.
  • Switching phones is manageable. Authenticator apps offer transfer or cloud-sync options, and your saved backup codes cover the gap — set both up before you need them.

Why phishing can't beat a passkey

A passkey is tied cryptographically to the real website it was created for, so it simply won't work on a look-alike phishing page — there's no code to type into the wrong box and nothing for an attacker to capture. That's a meaningful upgrade over app codes, which a convincing fake site can still trick you into entering. As more of your important accounts offer passkeys, adopting them removes one of the last ways a careful person still gets caught.

Key takeaways

  • 2FA adds a second proof so a leaked password alone can't get someone in.
  • Prefer an authenticator app or passkey over text-message codes.
  • Turn it on in order: email, money, password manager, then major accounts.
  • Passkeys replace passwords with your fingerprint or face — easier and phishing-proof.
  • Always save backup codes so a lost phone doesn't lock you out.

Quick quiz

A couple of quick questions to lock in what you just read. Nothing is saved — pick an answer to see if you got it.

  1. Which second factor is the weakest?

  2. Why are passkeys and hardware keys the strongest option?

  3. Which account should you protect with a second factor first?

Keep going

Subscribe for new lessons and a printable security checklist.

Get the plain-English security newsletter

One short email when we publish something useful. No spam, no fearmongering. Unsubscribe anytime.