Account security guide covering passwords, passkeys, MFA, recovery, sessions, and alerts. Private account security guide: passwords, passkeys, multifactor authentication, recovery, sessions, and alerts
Image: Privacy Notes

Guides

Private account security guide: passwords, passkeys, multifactor authentication, recovery, sessions, and alerts

A private account security guide covers passwords, passkeys, MFA, recovery codes, active sessions, login alerts, and lockout planning for safer accounts.

What to take away

  • Secure primary email and the password manager first; both can reset almost everything else.
  • A passkey stays on the authenticator or its sync account, so a stolen password alone will not sign in.
  • Register a second, independent sign-in method before you remove the old authenticator.
  • Recovery codes belong offline or in a vault separate from the device they rescue.
  • Review active sessions, connected apps, mail forwarding, and alerts on a schedule, not only after a scare.

Account security is a chain. A strong password does little when an attacker also controls the recovery email. Multifactor authentication helps, but an exposed backup code or a live session can walk past the prompt. The goal is independent controls plus a tested way back in.

Rank accounts by what they can reach

Start where a reset cascades. A compromised inbox can reset the password manager, the bank, and the work suite in one afternoon.

Account security inventory fields

  • Login address
  • Username
  • Sign-in methods
  • Recovery contacts
  • Backup codes
  • Trusted devices
  • Active sessions
  1. Primary email.
  2. Password manager and device account.
  3. Mobile carrier.
  4. Banking, tax, and government services.
  5. Cloud storage and publishing tools.
  6. Shopping, streaming, and forums.

For each, note these details:

  • login address
  • username
  • sign-in methods
  • recovery contacts
  • backup codes
  • trusted devices
  • active sessions
  • connected apps
  • where alerts arrive Keep the inventory itself out of an unprotected file.

Passwords where a password remains

Generate a distinct password per service and hold them in a protected manager. One reused password turns a single breach into a list of login attempts.

Password length vs symbol rules

Length

Security
Stronger
User behavior
Unique per service
Breach risk
Lower

Symbol rules

Security
Weaker
User behavior
Predictable patterns
Breach risk
Higher

Length beats symbol rules that people satisfy the same way every time. A password already exposed in a breach is spent, however long it is.

Do not send passwords by chat or email. Use delegated access, a family role, a team vault, or an emergency-access process when someone else genuinely needs in.

What a passkey changes

A passkey is public-key authentication. The service stores a public key; the private key stays with the authenticator or its protected sync system. Because the sign-in is bound to the real service, a lookalike login page collects nothing usable.

Device-bound vs synced passkeys

Device-bound

Storage
One authenticator
Portability
Stays on device
Loss risk
Device lost

Synced

Storage
Platform account
Portability
Travels across devices
Loss risk
Platform locked

Backup and portability differ. A device-bound passkey stays on one authenticator. A synced passkey travels through a platform account. Before enrolling, find out what happens when the device is lost, the platform account is locked, or you switch ecosystems.

Choosing a second method

Multifactor authentication combines different factor types, such as something you know and something you hold. Two passwords are not two factors.

MFA methods compared

Security keys

Phishing resistance
High
Ease of use
Medium
Recovery
Spare key

Authenticator apps

Phishing resistance
Medium
Ease of use
High
Recovery
Backup codes

Push prompts

Phishing resistance
Medium
Ease of use
High
Recovery
Device

SMS/email codes

Phishing resistance
Low
Ease of use
High
Recovery
Phone number

Common options are security keys, passkeys, authenticator apps, push prompts, and text or email codes. NIST's current authenticator guidance separates several authenticator types:

  • passwords
  • one-time codes
  • out-of-band secrets
  • recovery codes
  • session secrets
  • cryptographic authenticators

It notes that a manually typed one-time code is not phishing-resistant.

Those requirements target covered digital identity systems. They are useful concepts, not proof that a consumer account meets a federal assurance level. Use the strongest method you can operate and recover.

Recovery is a design decision

Register two independent ways to sign in wherever the service allows it. Store single-use recovery codes offline or in a vault separate from the device they rescue. Keep the recovery email and phone number current.

Recovery design checklist

  • Register two independent sign-in ways
  • Store recovery codes offline or separate vault
  • Keep recovery email and phone current
  • Avoid one phone, number, cloud, or room
  • Keep a spare security key elsewhere

Do not let every path run through one phone, one number, one cloud account, or one room. A spare security key kept elsewhere covers a lost primary. A synced passkey is only as safe as the platform account behind it.

Sessions, tokens, and connected apps

After sign-in, the service issues a session token that keeps you in. Review devices and sessions by date, location, and browser, then end the ones you do not recognize. After a suspected compromise, use "sign out everywhere" if the service offers it.

Then check what else holds access:

  • Third-party apps
  • App passwords
  • API tokens
  • Mail forwarding
  • Delegates
  • Automation rules Changing a password does not necessarily revoke a token.

Alerts are evidence, not instructions

Security alerts report several events:

  • Sign-ins
  • Password changes
  • Recovery edits
  • New authenticators
  • Data exports
  • Payments Open the account through a known app or a typed address, never through the message's own link or phone number.

Keep a second notification route current. An attacker inside the account can delete messages, so a separate address or device is what tells you something moved.

A response card for the first hour

Write the provider recovery pages, carrier contact, bank fraud line, device-lock steps, and one trusted person's number on a card you can reach without the locked device. Put no passwords and no reusable codes on it.

If a takeover happens, work from a known-clean device. Recover email and the password manager first. Revoke sessions, then replace the authenticators. Inspect forwarding and connected apps. Preserve the evidence. Tell the people or institutions affected. Report fraud to local police and the Canadian Anti-Fraud Centre.

Common questions

Is a passkey the same as a password?

No. A passkey uses a cryptographic key pair and service-bound authentication, so no shared secret is typed into the site. The private key stays with the authenticator or its sync account.

Is SMS multifactor authentication useless?

No. It still beats a password alone, but it is exposed to phishing and phone-number takeover. Move high-value accounts to a security key, a passkey, or an authenticator app where the service supports one.

Where should recovery codes be stored?

Offline, or in a protected vault separate from the device they rescue, with clear labels and limited access. Treat them as a second key to the account, because that is what they are.

Does changing a password end every session?

Not always. Use the service's session and device controls, and revoke third-party tokens and app passwords. A password change alone can leave an attacker's session running.

Who do I contact about a privacy complaint in Canada?

The Office of the Privacy Commissioner of Canada handles federal complaints, and provincial commissioners cover Quebec Law 25, Alberta PIPA, and similar statutes. For advice about your own situation, speak with a licensed lawyer rather than relying on a guide.

In this guide

  1. How to harden a high-value online account without locking yourself outHarden a high-value account by proving recovery control, adding a tested backup method, and clearing stale sessions before you change anything.
  2. Authentication methods compared: password managers, passkeys, security keys and SMS codesSix authentication methods compared on what proves access, phishing resistance, device dependence, backup and recovery, and account lockout risk.
  3. Account email, password, passkey, multifactor, recovery, session, device, and alert checklistAccount security checklist for email, passwords, passkeys, MFA, backup authenticators, recovery, sessions, trusted devices, connected apps, and alerts.

More in Guides

Latest from Guides Desk