Skip to main content

A Practical Guide to Strong Passwords, Passkeys, and MFA

Understand the difference between passwords, passkeys, and multi-factor authentication, then improve account security without locking yourself out.

23 views 3 minutes

Account security advice can sound contradictory: make passwords complex, do not change them too often, use passkeys, add another factor, and keep recovery codes. These instructions address different risks. A practical system uses unique credentials, phishing-resistant sign-in where available, and recovery options you have tested.

Use a unique password for every remaining password account

Password reuse turns one breach into many account takeovers. If an attacker learns a password from one service, automated tools can try the same email and password elsewhere. Length and uniqueness matter more than decorative substitutions such as replacing “a” with “@”.

A password manager can generate and store long random passwords. Protect the manager with a strong master password that you do not use anywhere else. Keep the application and operating system updated.

Understand what a passkey changes

A passkey creates a cryptographic credential for a particular service. The private part remains under the control of your device or credential provider; the service receives a public key. You unlock use of the credential with the local device method. Because the credential is associated with the genuine site, it is resistant to a fake login page stealing a reusable secret.

Before switching, learn whether your passkeys synchronize, how to use another device, and how account recovery works. Add a second recovery method where the service permits it.

Add multi-factor authentication

Multi-factor authentication (MFA) asks for more than one type of proof. A security key or passkey is generally more resistant to phishing than a code sent by text message. An authenticator-app code is still a meaningful improvement over password-only access, but a convincing fake site can sometimes relay the code in real time.

Start with email, the password manager, financial accounts, cloud storage, social media, and any account that can reset another account.

Store recovery information safely

  • Download or print recovery codes and keep them somewhere separate from the primary device.
  • Keep the recovery email and phone number current.
  • Register more than one security key for a critical account when supported.
  • Test recovery before an emergency, but never share a recovery code with someone who contacts you.

Respond to a suspected compromise

  1. Use a trusted device and go directly to the real service.
  2. Change the exposed password and sign out other sessions.
  3. Check recovery details, forwarding rules, connected applications, and recent activity.
  4. Change any reused password on other services.
  5. Save evidence and notify the provider or relevant institution.

Never approve an unexpected sign-in prompt just to make it disappear. Repeated prompts may be an attempt to wear down your attention.

A sensible upgrade order

Begin with your email and password manager, then secure accounts with payment, identity, or irreplaceable files. Replace reused passwords, enable the strongest MFA offered, save recovery codes, and adopt passkeys where the recovery model works for you.

Sources and further reading

Keep exploring
View all