Cybersecurity · 6 min read

2FA, passkeys:
the right order.

A unique password for every account is no longer enough on its own. But not all second factors are equal, and passkeys change the game without replacing everything.

PUBLISHED OCTOBER 2026 · 6 MIN READ

You use a unique password for every account. Great. But if one still leaks (phishing, malware, or a service breach), a second lock limits the damage. That is the role of two-factor authentication (2FA).

The remaining question is which one: SMS, app, hardware key, passkey. This article puts things in order, without jargon, and without promising the unbreakable.

99.9%
lower risk of compromise with multi-factor authentication, according to Microsoft
2
families of factors to combine: something you know, something you have

01 / THE PRINCIPLEA second factor is a second lock

In 2019, Microsoft stated that, based on its studies, an account with multi-factor authentication is more than 99.9% less likely to be compromised. The figure should be read in context (large-scale automated attacks), but the logic is sound: stealing a password is no longer enough.

A unique password for every account remains the foundation. The second factor is the floor above: it protects you the day the foundation is bypassed.

02 / NOT ALL FACTORS ARE EQUALFrom most fragile to most robust

An SMS code is better than nothing, but it can be intercepted or redirected. A time-based code app is stronger. The most robust methods are called phishing-resistant: physical security keys and passkeys, because the proof is bound to the legitimate site and cannot be replayed on a fake one.

⚠️ More fragile

  • SMS code: can be intercepted or diverted
  • Code typed on a page: can be relayed by a fake site
  • Security question: answer often guessable

✅ More robust

  • Time-based code app
  • Physical security key
  • Passkey bound to the legitimate site
  • No secret to retype on a fake site

03 / PASSKEYSDoes a passkey replace the password?

According to the FIDO Alliance, passkeys rely on public-key cryptography and are designed to resist phishing: there is no password to steal from the server nor to type on a fake site.

In practice, the transition is gradual: not every service offers them yet. The most realistic approach for now: enable passkeys where they exist, and keep unique passwords and a second factor everywhere else.

Not "all or nothing"

You do not have to choose between a password and a passkey. The two will coexist for a long time; what matters is leaving no critical account protected by a password alone.

04 / IN PRACTICEHygiene in six moves

QubKey has entry types dedicated to recovery codes and passkeys, so you can keep in one place, inside a local encrypted vault, what you will need the day you lose a device. Available for Windows and macOS, free during the beta.

Your 2FA plan, in order

  • Start with your primary email: it resets every other account.
  • Enable 2FA on banking, payment, and cloud, preferring an app or key over SMS.
  • Enable passkeys wherever the service offers them.
  • Keep recovery codes away from the device you are protecting.
  • Keep a unique password on every account that has no passkey yet.
  • Review your access once or twice a year: delete unused accounts.

This article is for informational purposes. No software is unbreakable, and no second factor alone guarantees against compromise. Follow each service's official instructions to enable multi-factor authentication.

One vault to keep it all.

Passwords, recovery codes, passkeys: keep them in a local vault for Windows and macOS. Free during the beta.

Discover QubKey