PASS PHRASES / FIELD NOTE
2FA: A Second Kind of Proof
Learn the difference between an extra question, an authenticator code and phishing-resistant authentication.
Two Steps Are Not Always Two Factors
Factors are commonly grouped as something you know, something you have and something you are. A phrase plus a security question is still two knowledge checks—not two independent categories.
A pass phrase plus a code from a separately controlled authenticator adds a possession factor. Some authenticators combine possession with a local PIN or biometric check in one flow.
Choose the Strongest Supported Option
- Passkeys and FIDO security keys can provide phishing-resistant sign-in when properly supported by the service.
- Authenticator-app codes add useful protection but can still be captured by a convincing fake sign-in page.
- Push approvals require attention. Deny unexpected requests; do not approve a prompt to make it stop.
- SMS can be a useful fallback when stronger options are unavailable, but phone-number takeover and message interception are additional risks.
Codes Are Not Support Tickets
Never tell a caller or chat agent a sign-in code, approval number or recovery code. A legitimate-looking caller may be trying to complete your sign-in on their own device.
Open the service through a trusted bookmark or known address. If you receive an unexpected prompt, deny it, inspect your account activity from the genuine site, and follow the service’s security process.
Do Not Lock Yourself Out
- Save recovery codes using the service’s instructions before relying on the new factor.
- Add a spare security key or second supported recovery method when appropriate.
- Test the backup path without deleting your working authenticator.
- Review remembered devices and recovery details periodically.
- When replacing a phone, move or re-enroll authenticators before wiping the old one.