Turn on MFA — and move to passkeys when you can
A second factor is the single most effective thing you can add to an account. Learn which kinds actually stop attackers, and why passkeys are the phishing-proof future.
The short version
Multi-factor authentication (MFA) means a password alone isn't enough to get in. Turn it on everywhere. An authenticator app is much stronger than text-message codes. A passkey is stronger still — it can't be phished at all — so choose passkeys wherever a site offers them.
Your password can be stolen, guessed, or phished. Multi-factor authentication adds a second requirement — something you have, like your phone or a security key — so that a stolen password on its own is a dead end. It is the highest-value five minutes you can spend on any important account.
Not all second factors are equal
Any MFA is better than none, but the type matters a great deal against a determined attacker.
- **Text-message (SMS) codes** — better than nothing, but the weakest option. Codes can be intercepted, and attackers can trick a phone carrier into moving your number to their SIM. Use it only when it's the only choice.
- **Authenticator app codes** — a 6-digit code that refreshes every 30 seconds, generated on your device with no network involved. Much stronger than SMS.
- **Push approvals** — a "was this you?" prompt you tap to approve. Convenient, but beware of approving prompts you didn't start (see below).
- **Passkeys and security keys** — the strongest. They prove you're on the genuine site using cryptography, so there is nothing for a fake site to steal.
MFA fatigue: don't approve a prompt you didn't start
Attackers who already have your password will spam you with push approvals hoping you tap "approve" to make it stop. If a prompt appears when you weren't signing in, deny it and change your password — someone else has it.
What a passkey is, in plain terms
A passkey replaces your password with a secret that never leaves your device and is unique to each site. When you sign in, your phone or laptop proves you're the owner — usually with your fingerprint, face, or device PIN — and proves it directly to the real website. There is no code to type and no password to steal. Crucially, a passkey will not work on a fake look-alike site, because it is cryptographically bound to the real one. That's why passkeys are called phishing-resistant: even if you're fooled by a convincing fake, the passkey isn't.
Passkeys sync securely across your own devices through your phone or browser's built-in system, so setting one up on your phone usually means it's ready on your laptop too. Major sites — email providers, banks, social networks — increasingly offer them, often labeled "passkey" or "sign in without a password."
What to do today
- Turn on MFA for your email first — it's the reset path for every other account.
- Prefer an authenticator app or passkey over SMS wherever the site allows it.
- Create passkeys on the sites that offer them; keep your existing MFA as a backup until passkeys are fully set up.
- Save your backup or recovery codes somewhere safe in case you lose your phone.