A Password Should Not Be Your Only Lock
A strong password is important, but it should not be your account’s only defence. Multifactor authentication adds another barrier when passwords are stolen or exposed.
A strong password is important, but a password alone should not be the only thing protecting an important account.
If someone steals, guesses or obtains your password through a data breach or phishing attack, they may be able to use it to impersonate you and access your account.
Multifactor authentication (MFA) adds another layer of protection by requiring an additional way to verify that you are really the person trying to sign in.
Depending on the account or service, that additional verification might involve an authenticator app, a physical security key, a fingerprint or face scan, or a one-time code.
However, not all MFA methods provide the same level of protection.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recommends using the strongest MFA method available, particularly phishing-resistant MFA. Physical security keys are among the strongest options because they can provide strong protection against phishing attacks.
Authenticator apps can also provide strong additional protection, particularly when they use features such as number matching. Text message or email codes offer weaker protection and are better used when stronger options are unavailable.
MFA does not make an account impossible to compromise. But it creates an important additional barrier: stealing your password alone may no longer be enough for someone to gain access.
Why It Matters
Adding another authentication factor can significantly strengthen your accounts when passwords are stolen, guessed or exposed.