Turn on MFA, and move to passkeys when you can
A second factor is the single most effective thing you can add to an account. Learn which kinds actually stop attackers, and why passkeys are the phishing-proof future.
The short version
Multi-factor authentication (MFA) means a password alone isn't enough to get in. Turn it on everywhere. An authenticator app is much stronger than text-message codes. A passkey is stronger still (it can't be phished at all) so choose passkeys wherever a site offers them.
Your password can be stolen, guessed, or phished. Multi-factor authentication adds a second requirement (something you have, like your phone or a security key) so that a stolen password on its own is a dead end. It is the highest-value five minutes you can spend on any important account.
Not all second factors are equal
Any MFA is better than none, but the type matters a great deal against a determined attacker.
- Text-message (SMS) codes: better than nothing, but the weakest option. Codes can be intercepted, and attackers can trick a phone carrier into moving your number to their SIM. Use it only when it's the only choice.
- Authenticator app codes: a 6-digit code that refreshes every 30 seconds, generated on your device with no network involved. Much stronger than SMS.
- Push approvals: a "was this you?" prompt you tap to approve. Convenient, but beware of approving prompts you didn't start (see below).
- Passkeys and security keys: the strongest. They prove you're on the genuine site using cryptography, so there is nothing for a fake site to steal.
MFA fatigue: don't approve a prompt you didn't start
Attackers who already have your password will spam you with push approvals hoping you tap "approve" to make it stop. If a prompt appears when you weren't signing in, deny it and change your password. Someone else has it.
What a passkey is, in plain terms
A passkey replaces your password with a secret that never leaves your device and is unique to each site. When you sign in, your phone or laptop proves you're the owner (usually with your fingerprint, face, or device PIN) and proves it directly to the real website. There is no code to type and no password to steal. Crucially, a passkey will not work on a fake look-alike site, because it is cryptographically bound to the real one. That's why passkeys are called phishing-resistant: even if you're fooled by a convincing fake, the passkey isn't.
Passkeys sync securely across your own devices through your phone or browser's built-in system, so setting one up on your phone usually means it's ready on your laptop too. Major sites (email providers, banks, social networks) increasingly offer them, often labeled "passkey" or "sign in without a password."
What to do today
- Turn on MFA for your email first: it's the reset path for every other account.
- Prefer an authenticator app or passkey over SMS wherever the site allows it.
- Create passkeys on the sites that offer them; keep your existing MFA as a backup until passkeys are fully set up.
- Save your backup or recovery codes somewhere safe in case you lose your phone.