goJumboGPT

Security

Signing in safely: 2FA, passkeys and account recovery

Two-factor codes, authenticator apps, SIM swap risk, passkeys, security keys, biometrics and recovery options, explained without jargon or scare stories.

6 articles in this hub

A password on its own is one secret that can be stolen once and then used anywhere. The second step at sign-in is what makes that theft survivable, and it is also the part most people set up badly: codes sent by text message, no backup of anything, and a recovery address they stopped using years ago. What follows covers the whole moment of signing in, from two-factor codes to passkeys that drop the password altogether.

If you are starting from nothing, read what two-factor authentication actually does, then get your codes off text messages by setting up an authenticator app with working backups. Where a site offers them, passkeys take the password out of the process and cannot be handed to a fake login page. If your face or fingerprint unlocks any of this, the caveats are worth reading before you rely on it.

The step nearly everyone skips is the last one. Arrange account recovery before you need it, while you still have the phone, the backup codes and the old address in front of you. The morning your handset goes missing is a bad time to discover what is missing.

Articles in this hub