Lesson 1 of 4 · Module 02

Passwords, Passkeys, and MFA

A strong sign-in protects an account even when another website is breached. The safest practical setup combines a unique credential with an additional verification method.

8 min read · Beginner friendly

Make every account unique

Password reuse turns one company’s breach into a key for many accounts. A password manager can create and store long, unique passwords. Passkeys use cryptography tied to your device and resist ordinary password phishing.

Add another layer

Multi-factor authentication asks for another proof after a password. An authenticator app, passkey, or security key is generally safer than a text message, though any MFA is usually better than none.

  • Protect email and financial accounts first
  • Store recovery codes safely and offline
  • Never approve a sign-in prompt you did not initiate