Learning Guide
Online Account Safety
An account connects a person to a service through a sign-in method. A password is one method; a passkey or a second verification step is another. Learning what these methods do helps you understand the choices offered by a provider.
Why unique passwords matter
If two accounts share a password, exposure of that password can put both accounts at risk. A unique password limits that reuse. Longer passwords or passphrases can be easier to remember while still being difficult to guess. Avoid names, birthdays, and other details that people can find publicly. A password manager can help create and store different passwords; review its security and recovery information before choosing one.
What a second sign-in step does
Multi-factor authentication adds a separate check, such as a security key or approval on a registered device. Its purpose is to make possession of a password alone less useful. A one-time code is private: someone who asks you to read it aloud may be trying to complete a sign-in as you. Passkeys, where available, use a different mechanism and can reduce risks from password-based phishing.
A simple example
Imagine your library account and photo account use the same password. If the library password is exposed, an attacker may try it on the photo account. Different passwords reduce that opportunity. An additional sign-in check adds protection, but no method makes an account immune to every risk.
Learning exercise: Without entering any real credentials, write down the difference between a password, a one-time code, and a recovery code. Which of these should you share with someone who unexpectedly contacts you? None of them.