Skip to content
PURPLEDUEL

MFA and passkeys: what they are and how to use them to protect your accounts

Updated · 3 min read

A password alone is a single point of failure: if it is guessed, phished or found in a data breach, whoever holds it gets in. Multi-factor authentication (MFA) and passkeys exist to make a stolen password useless. Switching them on for your important accounts is one of the most effective and cheapest things you can do.

The three kinds of factor

MFA requires at least two factors of different kinds. That is why two passwords are not MFA: they are "something you know" twice.

The methods compared

MethodHow it worksWeak points
SMS codeyou receive a six-digit code on your phonecan be intercepted by techniques such as SIM swapping; can be stolen with a fake page
Authenticator app (TOTP)an app generates a code that changes every 30 secondscan still be typed into a phishing page
Push notificationyou approve a sign-in with a tap"MFA fatigue": so many prompts that the user approves one by mistake
Security key (FIDO2)a physical device confirms the sign-inmust be looked after, and you need a spare
Passkeya cryptographic key pair tied to the sitedepends on the security of the device and of the account that syncs them

Any MFA is better than none: even an SMS code blocks the vast majority of automated attacks. But the methods differ on one point: do they resist phishing?

How a passkey works

  1. When you create a passkey on a site, your device generates a key pair: a public key, handed to the site, and a private key that stays on the device and is never transmitted.
  2. At the next sign-in the site sends a random challenge, and the device signs it with the private key only after you confirm with fingerprint, face or PIN.
  3. The site checks the signature with the public key. There is no password to type and no shared secret to steal.

A passkey is tied to the domain of the real site: on a fake page imitating your bank, the browser does not even offer it, so there is no way to be tricked. That is what makes it phishing-resistant, unlike passwords and six-digit codes.

A worked example

An employee receives an email that looks like it comes from a company service and types her password and authenticator code into a fake page. The attacker uses them immediately on the real site and gets in. If she had used a passkey or a FIDO2 key, the fake page could not have obtained anything usable, because the cryptographic answer is bound to the address of the genuine site.

How to defend: the steps to take today

  1. Start with your main email: whoever controls your inbox can reset every other password.
  2. Then move on to banking, social media, cloud storage and work, choosing passkeys or an authenticator app over SMS wherever possible.
  3. Keep your recovery codes printed or in a password manager: you need them if you lose your phone.
  4. Register more than one device (two security keys, or passkeys on two devices) so you do not get locked out.
  5. Never approve a request you did not start: if a sign-in prompt arrives while you are not signing in, deny it and change your password.
  6. Use a password manager for everything that does not support passkeys yet, with long unique passwords.

Passkeys are the most concrete answer to the phishing problem described in the guide to phishing: if there is no password to hand over, there is nothing to steal.

Keep reading