Signing in safely: 2FA, passkeys and account recovery
Two-factor codes, authenticator apps, SIM swap risk, passkeys, security keys, biometrics and recovery options, explained without jargon or scare stories.
A password on its own is one secret that can be stolen once and then used anywhere. The second step at sign-in is what makes that theft survivable, and it is also the part most people set up badly: codes sent by text message, no backup of anything, and a recovery address they stopped using years ago. What follows covers the whole moment of signing in, from two-factor codes to passkeys that drop the password altogether.
If you are starting from nothing, read what two-factor authentication actually does, then get your codes off text messages by setting up an authenticator app with working backups. Where a site offers them, passkeys take the password out of the process and cannot be handed to a fake login page. If your face or fingerprint unlocks any of this, the caveats are worth reading before you rely on it.
The step nearly everyone skips is the last one. Arrange account recovery before you need it, while you still have the phone, the backup codes and the old address in front of you. The morning your handset goes missing is a bad time to discover what is missing.
Articles in this hub
- Two-factor authentication explained in plain EnglishWhat the second factor really is, which attacks it blocks, which ones it does not, the accounts to protect first, and the objections that keep people from turning it on.
- Setting up an authenticator app properly, including backupsHow to move your two factor codes to an app without locking yourself out: what the QR code contains, where to store recovery codes, and how to handle a new phone.
- Passkeys explained: signing in with no password at allWhat a passkey is, how the phishing resistance actually works, what happens when you lose the device, and whether it is time to switch your main accounts over.
- Face and fingerprint unlock: safer than a PIN, with caveatsWhat happens when you unlock with your face, why the biometric never leaves the device, where it is weaker than a passcode, and the legal difference worth knowing.
- Account recovery: set it up before you need itRecovery is how most accounts are actually lost and stolen: the settings to fix today, the recovery contacts and codes to store, and the fifteen minute audit that prevents a very bad week.
- Your email account is the master key: lock it properlyWhy the email account is the single most valuable target, the settings that stop a silent takeover, and the hidden forwarding rules attackers leave behind.