2FA, passkeys:
the right order.
A unique password for every account is no longer enough on its own. But not all second factors are equal, and passkeys change the game without replacing everything.
You use a unique password for every account. Great. But if one still leaks (phishing, malware, or a service breach), a second lock limits the damage. That is the role of two-factor authentication (2FA).
The remaining question is which one: SMS, app, hardware key, passkey. This article puts things in order, without jargon, and without promising the unbreakable.
01 / THE PRINCIPLEA second factor is a second lock
In 2019, Microsoft stated that, based on its studies, an account with multi-factor authentication is more than 99.9% less likely to be compromised. The figure should be read in context (large-scale automated attacks), but the logic is sound: stealing a password is no longer enough.
A unique password for every account remains the foundation. The second factor is the floor above: it protects you the day the foundation is bypassed.
02 / NOT ALL FACTORS ARE EQUALFrom most fragile to most robust
An SMS code is better than nothing, but it can be intercepted or redirected. A time-based code app is stronger. The most robust methods are called phishing-resistant: physical security keys and passkeys, because the proof is bound to the legitimate site and cannot be replayed on a fake one.
⚠️ More fragile
- SMS code: can be intercepted or diverted
- Code typed on a page: can be relayed by a fake site
- Security question: answer often guessable
✅ More robust
- Time-based code app
- Physical security key
- Passkey bound to the legitimate site
- No secret to retype on a fake site
03 / PASSKEYSDoes a passkey replace the password?
According to the FIDO Alliance, passkeys rely on public-key cryptography and are designed to resist phishing: there is no password to steal from the server nor to type on a fake site.
In practice, the transition is gradual: not every service offers them yet. The most realistic approach for now: enable passkeys where they exist, and keep unique passwords and a second factor everywhere else.
Not "all or nothing"
You do not have to choose between a password and a passkey. The two will coexist for a long time; what matters is leaving no critical account protected by a password alone.
04 / IN PRACTICEHygiene in six moves
QubKey has entry types dedicated to recovery codes and passkeys, so you can keep in one place, inside a local encrypted vault, what you will need the day you lose a device. Available for Windows and macOS, free during the beta.
Your 2FA plan, in order
- Start with your primary email: it resets every other account.
- Enable 2FA on banking, payment, and cloud, preferring an app or key over SMS.
- Enable passkeys wherever the service offers them.
- Keep recovery codes away from the device you are protecting.
- Keep a unique password on every account that has no passkey yet.
- Review your access once or twice a year: delete unused accounts.
One vault to keep it all.
Passwords, recovery codes, passkeys: keep them in a local vault for Windows and macOS. Free during the beta.
Discover QubKey