All lessons Leer en español

Everyday security · Unit 01 · Lesson 2 of 6

Stronger sign-ins

Protect the accounts you care about without turning every login into homework.

5 minready

After this lesson you can

  • explain why passwords should be unique to each account
  • distinguish a passkey from a password or one-time code
  • prepare a safe account recovery option

You used one excellent password for email, a game, and a shop. The shop has a data breach. Is your email still protected?

A password can be hard to guess and still be the wrong choice to reuse. A leak from one service can put other accounts using that password at risk.

1. Give accounts separate protection. 2. Add a stronger sign-in method. 3. Keep a safe way to recover access.

Give each account its own secret

A password manager can generate and store long, unique passwords so you do not have to memorize them all. Protect the manager itself with a strong sign-in and a recovery plan. Start with your main email account: it often receives reset links for other accounts.

Add another layer

Where available, a passkey can replace a password. Your device or password manager holds a cryptographic credential bound to the real service. You often unlock it with a device PIN, fingerprint, or face check. That binding helps resist fake sign-in sites; it does not make every action in the account safe.

For password accounts, turn on multifactor authentication. A security key offers phishing resistance. Authenticator codes and text messages can still add protection, but codes can be stolen by phishing. Two passwords are still one kind of evidence.

Approve only sign-ins you started. Enter codes only in a sign-in flow you initiated on the real service, never as a reply to someone requesting them.

Keep a way back in

Check your recovery contact details. Store backup codes securely, somewhere you can access if your phone is lost.

Takeaway: Unique passwords, stronger sign-ins, and recovery work together.

Terms you met

passkeymultifactor authentication

Check yourself

No timer. No penalties. Read the explanation and try again whenever you like.

  1. A game's password leaks. What limits the damage to your email account?

    Show the answer

    Correct answer: Use a different, independently generated password for email. A leak from one service then does not reveal the other service's password.

  2. Why can a passkey help against a lookalike sign-in page?

    Show the answer

    Correct answer: It is bound to the service it was created for. The browser or device checks that binding instead of handing a reusable password to any page.

  3. You receive an approval prompt when you are not signing in. What next?

    Show the answer

    Correct answer: Deny it and check account activity through the official app. An unexpected prompt deserves a separate check. Do not approve a request you did not start.

  4. Before replacing your phone, what should you check?

    Show the answer

    Correct answer: That recovery methods work and backup codes are stored safely. Plan a route back in that does not depend only on the phone you might lose.

Try it

  • WriteFor a fictional email account, make a three-line plan: its sign-in method, its extra protection, and how the owner could recover it after losing a phone. Never write a real password or recovery code here.
References