
Most account takeovers are not clever hacks. They happen because a password was reused and leaked somewhere else, or because someone typed a code into a fake login page. A three-part setup blocks almost all of it.
In this article
1. A password manager
A password manager creates and remembers a long, unique password for every site. You remember one strong master password.
- Built-in options: the password managers in Chrome, Edge, Firefox, Safari/iCloud Keychain and Google Password Manager.
- Dedicated apps (free and paid) add sharing, security reports and cross-platform sync.
2. Passkeys where you can
A passkey replaces the password with a cryptographic key stored on your phone or computer, unlocked with your fingerprint, face or PIN. Passkeys cannot be phished: they only work on the real website they were created for. Google, Microsoft, Apple, Amazon and many banks and apps support them — look for “Create a passkey” in account security settings.
3. Two-factor authentication (2FA)
| Method | Protection | Notes |
|---|---|---|
| Passkey / security key | Strongest | Phishing-resistant |
| Authenticator app (codes) | Strong | Works offline; back up or transfer when you change phones |
| Push approval (“Is this you?”) | Good | Never approve a prompt you did not trigger |
| SMS codes | Better than nothing | Vulnerable to SIM swap and phishing |
Save your backup codes
When you turn on 2FA, sites give you one-time backup codes. Store them in your password manager or print them. Losing your phone without backup codes is the most common way people lock themselves out.
Red flags to remember
- No real company asks you to read out an OTP over the phone.
- Check the address bar before typing a password — or use passkeys and the problem disappears.
- Urgency (“account blocked in 1 hour”) is a scam signal.