Password & accounts. Updated 2026-09-13. About 5 minutes to read.
Turn on two-factor authentication for your email account today, use a passkey or authenticator app instead of text messages, and save your backup codes offline.
Two-factor authentication means a stolen password is not enough to get into your account. The attacker also needs a second thing, such as a code from your phone, a tap on a security key or your face or fingerprint on a passkey. Any second factor stops most mass attacks on reused passwords.
The methods are not equal. Text message codes and app codes can be phished in real time, while passkeys and hardware security keys cannot. This guide ranks the options, explains passkeys in plain terms and gives you a setup order that protects the accounts that matter first.
A criminal who convinces your carrier to move your number to their SIM receives your codes. A phishing page can also ask for the code and use it within seconds. That is why NIST's digital identity guidelines treat phone network codes as a restricted method.
Still, text codes stop the huge volume of attacks that simply try leaked passwords. If a site only offers text codes, turn them on, and add a port-out lock with your carrier.
A passkey is a pair of cryptographic keys. The website keeps the public half. The private half stays on your phone, computer or password manager, and you approve each sign-in with the same face, fingerprint or PIN you use for the device. Nothing reusable is typed or sent.
Your device only uses a passkey on the website it was created for. A look-alike domain cannot ask for it, so there is nothing for a phishing page to capture. That is the property text and app codes lack. Passkeys that sync through Apple, Google or a password manager also survive losing one device.
Losing your only second factor with no backup codes can mean losing the account for good. Set up the backup before you need it.
Journalists, activists, political staff, executives and anyone being targeted should consider hardware keys. Apple's Security Keys for Apple Account need at least two FIDO Certified keys and iOS 16.3, iPadOS 16.3 or macOS Ventura 13.2 or later. On an iPhone, add them in Settings, tap your name, then Sign-In and Security, then Two-Factor Authentication, then Security Keys.
Google's Advanced Protection Program can be enrolled with passkeys or security keys. It lets only Google apps and verified third-party apps access your data, and account recovery takes extra steps. That friction is the point.
Yes. It blocks most automated attacks using leaked passwords. It is the weakest option, so switch to an authenticator app, passkey or security key wherever the site offers one.
Use a backup code or your second method to sign in, then set up the app again on the new phone. If the app backed up to your Google or Microsoft account, restore it there. Without any backup, you face each site's account recovery process.
A passkey combines something you have, your device, with something you are or know, your face, fingerprint or PIN. Many sites treat it as a replacement for both the password and the second factor, and it resists phishing better than codes.
For ordinary accounts, it is convenient and much better than no second factor. For your email and the password manager itself, keep the second factor separate, such as a security key or authenticator app.
Most people do not. Passkeys give similar phishing resistance with the devices you already own. Hardware keys make sense if you are a likely target or want a backup that does not depend on your phone.