Skip to content

Turn on MFA — and move to passkeys when you can

A second factor is the single most effective thing you can add to an account. Learn which kinds actually stop attackers, and why passkeys are the phishing-proof future.

EveryoneIntro7 min· Updated Jul 22, 2026
TL;DR

The short version

Multi-factor authentication (MFA) means a password alone isn't enough to get in. Turn it on everywhere. An authenticator app is much stronger than text-message codes. A passkey is stronger still — it can't be phished at all — so choose passkeys wherever a site offers them.

Your password can be stolen, guessed, or phished. Multi-factor authentication adds a second requirement — something you have, like your phone or a security key — so that a stolen password on its own is a dead end. It is the highest-value five minutes you can spend on any important account.

Not all second factors are equal

Any MFA is better than none, but the type matters a great deal against a determined attacker.

  • **Text-message (SMS) codes** — better than nothing, but the weakest option. Codes can be intercepted, and attackers can trick a phone carrier into moving your number to their SIM. Use it only when it's the only choice.
  • **Authenticator app codes** — a 6-digit code that refreshes every 30 seconds, generated on your device with no network involved. Much stronger than SMS.
  • **Push approvals** — a "was this you?" prompt you tap to approve. Convenient, but beware of approving prompts you didn't start (see below).
  • **Passkeys and security keys** — the strongest. They prove you're on the genuine site using cryptography, so there is nothing for a fake site to steal.
Pitfall

MFA fatigue: don't approve a prompt you didn't start

Attackers who already have your password will spam you with push approvals hoping you tap "approve" to make it stop. If a prompt appears when you weren't signing in, deny it and change your password — someone else has it.

What a passkey is, in plain terms

A passkey replaces your password with a secret that never leaves your device and is unique to each site. When you sign in, your phone or laptop proves you're the owner — usually with your fingerprint, face, or device PIN — and proves it directly to the real website. There is no code to type and no password to steal. Crucially, a passkey will not work on a fake look-alike site, because it is cryptographically bound to the real one. That's why passkeys are called phishing-resistant: even if you're fooled by a convincing fake, the passkey isn't.

Passkeys sync securely across your own devices through your phone or browser's built-in system, so setting one up on your phone usually means it's ready on your laptop too. Major sites — email providers, banks, social networks — increasingly offer them, often labeled "passkey" or "sign in without a password."

What to do today

  • Turn on MFA for your email first — it's the reset path for every other account.
  • Prefer an authenticator app or passkey over SMS wherever the site allows it.
  • Create passkeys on the sites that offer them; keep your existing MFA as a backup until passkeys are fully set up.
  • Save your backup or recovery codes somewhere safe in case you lose your phone.