Notebookcheck Logo

A password alone isn't enough: How to really secure your accounts

A hand holds a smartphone and unlocks it using the fingerprint sensor on the lock screen.
ⓘ Im Zion / Pexels
A passkey is unlocked using a fingerprint; the private key never leaves the device.
A strong password alone won't be enough in 2026. Data breaches and phishing get past it. Two-factor authentication and, above all, passkeys make your accounts truly secure. We show you which methods protect best, how to set them up in a few minutes, and who should consider a hardware key.

Do you know that feeling when yet another report about a data breach comes out and you wonder if your password was among those compromised? That concern is justified. Billions of login credentials from past breaches are circulating, and modern phishing sites are stealing passwords in real time. A strong password is important, but it’s just one hurdle. If it’s compromised, your account is wide open. The good news: With two-factor authentication, or better yet a passkey, you can make your accounts a lot more secure in a few minutes. The BSI recommends exactly that.

Why a password alone is no longer enough

Passwords have three vulnerabilities that even the most complex password cannot protect against. First, data breaches: If a service is hacked, millions of login credentials end up in circulation, and anyone who reuses the same password loses multiple accounts at once. Second, phishing: A deceptively genuine login page asks for your password, and you voluntarily enter it. Third, SIM swapping: Fraudsters take over your cell phone number and use it to intercept even SMS codes. According to the FBI, losses totaled around $26 million in 2024 alone, and SIM swapping remains one of the most frequently reported types of attacks. Two-factor authentication adds a second hurdle that an attacker cannot easily overcome.

An overview of the methods, from SMS to passkeys

Not all two-factor authentication methods are created equal. A code sent via text message or email is the best-known option and better than nothing, but it is also the weakest. An authenticator app on your phone generates a fresh code every 30 seconds, the so-called TOTP, locally on the device and without touching the cellular network. This makes it immune to SIM swapping. Passkeys take it a step further: Instead of a code, you store a cryptographic key on your device, unlocked via fingerprint, facial recognition, or PIN. The private key never leaves your device, as described by the FIDO Alliance. A hardware key, such as a YubiKey, is a small USB or NFC dongle that implements the same principle in hardware. And in Germany, there are two additional highly secure methods, chipTAN and the national ID card, specifically for banking and government agencies.

What really protects, according to the BSI

Why is one two-factor authentication method more secure than another? The BSI has conducted a technical evaluation of common methods, and the key difference is real-time protection against phishing. With SMS and email, an attacker can easily forward the code via an intermediary server while you’re unsuspectingly typing it into their fake website. According to the BSI, authenticator apps also do not provide reliable protection against such real-time attacks or data leaks. Passkeys and hardware keys, on the other hand, are tied to the website’s actual address. They simply do not work on a fake site, rendering the phishing attempt ineffective. According to the BSI, chipTAN and the national ID card are even resistant to all attacks considered. The BSI makes one basic assumption here: a strong password as a foundation and two separate devices.

The BSI rates these methods differently: passkeys, hardware keys, chipTAN and ID cards protect against real-time phishing, while SMS and authenticator apps do not.

Set up passkeys in a few minutes

Passkeys are the easiest way to achieve high security because you typically unlock them with what you already use anyway: your fingerprint or your face. They work on iPhones running iOS 16 or later, on Android devices running version 9 or later, and on Windows 10 and 11, in all current browsers. They’re supported by Google, Apple, Microsoft, Amazon, PayPal, and GitHub, among others, and the list is growing rapidly. According to the FIDO Alliance, there will be around five billion active passkeys worldwide by 2026, and awareness has now reached 90 percent.

Here’s how to set them up: On Google, go to g.co/passkeys; on Apple, go to appleid.apple.com; on Microsoft, go to account.microsoft.com; and create a passkey there with just a few clicks. After that, you confirm logins with your fingerprint or face and stop typing passwords. On a shared computer, the Authenticator app is a good alternative: install an app like Google Authenticator, Microsoft Authenticator, or the open-source Aegis; go to the “Security” section of the service and scan the QR code it shows. That is all, an app instead of an SMS code.

A hardware key for your most sensitive account

If you want to provide maximum security for your most important account, say the email inbox where all password resets land, reach for a hardware key. These are FIDO2 tokens like the YubiKey (available here on Amazon) or Google’s Titan Key, which you briefly plug in or hold up to your phone via NFC when logging in. They’re just as resistant to phishing as passkeys, but they’re a separate device that no one can copy remotely.

A hardware key is briefly inserted during login; it offers the same level of protection against phishing as a passkey.

Some context, because it made headlines in 2024: Researchers demonstrated with the EUCLEAK attack that certain YubiKeys from the 5 series with firmware versions prior to 5.7 can be cloned. That sounds dramatic, but it’s hardly relevant for ordinary users. The attack requires physical access to the device and expensive specialized lab equipment; it is not a remote attack. Yubico has patched the vulnerability with firmware version 5.7. In practical terms, this simply means: make sure to buy a current model. One more tip: get two keys, one as a spare.

Don’t forget recovery, and here’s who should do what

The most common vulnerability isn’t two-factor authentication itself, but the recovery process. If a service lets you log back in via a simple email after losing your phone, the entire two-factor security is compromised. The BSI therefore recommends a two-step recovery process. Store the backup codes that every service offers during setup in a safe place, either offline or in a password manager. With hardware keys, the second key serves precisely as this backup.

So, what’s best for whom? For most accounts, a passkey offers the best balance of security and convenience, and often eliminates the need for a password entirely. Where passkeys aren’t yet available, use an authenticator app instead of SMS. And secure your most sensitive account with a hardware key. The effort is minimal, but the difference is significant.

Google LogoAdd as a preferred source on Google
Mail Logo
static version load dynamic
Loading Comments
Comment on this article
> Expert Reviews and News on Laptops, Smartphones and Tech Innovations > Reviews > A password alone isn't enough: How to really secure your accounts
Steffen Zahn, 2026-07-20 (Update: 2026-07-20)