Passwords, Passkeys and 2FA: A Practical Setup for Normal People

Passwords, Passkeys and 2FA: A Practical Setup for Normal People
⏱ 2 min readUpdated 27 September 2026

Most account takeovers are not clever hacks. They happen because a password was reused and leaked somewhere else, or because someone typed a code into a fake login page. A three-part setup blocks almost all of it.

In this article
  1. 1. A password manager
  2. 2. Passkeys where you can
  3. 3. Two-factor authentication (2FA)
  4. Save your backup codes
  5. Red flags to remember

1. A password manager

A password manager creates and remembers a long, unique password for every site. You remember one strong master password.

  • Built-in options: the password managers in Chrome, Edge, Firefox, Safari/iCloud Keychain and Google Password Manager.
  • Dedicated apps (free and paid) add sharing, security reports and cross-platform sync.
💡 Use the manager’s security check to find reused and leaked passwords. Fix your email account first — it is the key that resets everything else.

2. Passkeys where you can

A passkey replaces the password with a cryptographic key stored on your phone or computer, unlocked with your fingerprint, face or PIN. Passkeys cannot be phished: they only work on the real website they were created for. Google, Microsoft, Apple, Amazon and many banks and apps support them — look for “Create a passkey” in account security settings.

3. Two-factor authentication (2FA)

Method Protection Notes
Passkey / security key Strongest Phishing-resistant
Authenticator app (codes) Strong Works offline; back up or transfer when you change phones
Push approval (“Is this you?”) Good Never approve a prompt you did not trigger
SMS codes Better than nothing Vulnerable to SIM swap and phishing

Save your backup codes

When you turn on 2FA, sites give you one-time backup codes. Store them in your password manager or print them. Losing your phone without backup codes is the most common way people lock themselves out.

Red flags to remember

  • No real company asks you to read out an OTP over the phone.
  • Check the address bar before typing a password — or use passkeys and the problem disappears.
  • Urgency (“account blocked in 1 hour”) is a scam signal.