Passkeys and login security
Most account takeovers still start with a reused password or a phished code. This section covers what actually stops them: passkeys, phishing-resistant second factors, sensible recovery options and a password manager for everything that has not moved on yet.
20 pages
In this section
Account recovery: how to plan it before you need it
Locked out of Google, Apple or your email? Set up recovery options, backup codes and a trusted contact now, and test them, so a lost phone is an annoyance.
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Backup codes: what they are and where to keep them
Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.
Data breach: what to do now, step by step
Your email was in a breach? Check Have I Been Pwned or the HPI Identity Leak Checker, change the right passwords, switch on 2FA and watch for follow-up scams.
Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
Hardware security keys explained: how they work
A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.
How authenticator codes (TOTP) work and how to use them
TOTP codes are the six-digit numbers in authenticator apps. See how they are generated, why they work offline, their limits and how to back them up safely.
How password managers work and why they are safe
A password manager keeps your logins in an encrypted vault that only your master password opens. How it works, the real risks and how to start in an afternoon.
How to set up passkeys on iPhone, Android, Windows and Mac
Step-by-step passkey setup for iPhone, Android, Windows and Mac, plus Google, Microsoft, Apple, Amazon and PayPal. Includes backup and recovery tips.
Login security for small businesses: a practical plan
Protect your team's accounts with SSO, mandatory MFA and a team password manager. A short plan with offboarding, admin rules and a note on NIS2 for small firms.
Passkeys explained: how passwordless login works
Passkeys replace passwords with a key on your device. Learn how they work, where they are stored, what happens if you lose a phone and who supports them.
Passkeys vs passwords: which is safer and easier?
Passkeys beat passwords on phishing, reuse and breaches. A fair comparison of security, convenience, recovery and compatibility, and when passwords still do.
Phishing-resistant MFA: what qualifies and what does not
Phishing-resistant MFA stops fake login pages from stealing your second factor. Which methods qualify (passkeys, security keys) and which do not (SMS, codes).
Secure your email account: the key to everything else
Your email can reset almost every other account. Check password, 2FA, recovery options, forwarding rules and connected apps in about 20 minutes, step by step.
Sign in with Google, Apple or Facebook: pros and cons
Social login saves passwords but ties accounts to one provider. See what Google, Apple and Facebook share, when it makes sense and how to review connections.
SIM swapping: how it works and how to protect yourself
SIM swapping lets criminals hijack your phone number and the SMS codes sent to it. How the scam works, the warning signs and a practical protection checklist.
Single sign-on (SSO) explained: benefits and risks
Single sign-on lets one login open many services, from work apps to Sign in with Google. How SSO works, its benefits and risks and how to use it safely.
SMS codes as a second factor: risks and better options
SMS codes beat having no second factor but are the weakest kind. Learn why they can be intercepted or redirected, when they are fine and what to use instead.
Strong passwords in 2026: what still matters
Length beats complexity: NIST and BSI advice on passphrases, unique passwords, password managers and why you no longer need to change passwords on a schedule.
Two-factor authentication (2FA) explained: types and setup
What two-factor authentication is, how SMS, apps, push and security keys differ, which to choose and how to switch it on without locking yourself out.
Other sections
Digital identity in Europe
eIDAS 2.0, the EU Digital Identity Wallet, levels of assurance and qualified signatures, explained without the legal fog. What changes for citizens and for businesses.
Digital ID by country
How online identification works in every EU and EEA country, Switzerland, the UK and Turkey: the national eID, the wallet status, and how to get it.
Reviews and comparisons
Independent comparisons of password managers, hardware security keys and authenticator apps, with a close look at where your data is stored and which providers are European.
Identity standards explained
OpenID Connect, OAuth 2.0, SAML, FIDO2/WebAuthn, OpenID4VP and verifiable credentials explained in plain language, with what each one is actually for.
History of open identity
From OpenID 1.0 and the European OpenID community of 2007 to OpenID Connect and the EU wallet: how the idea of a portable, user-controlled login developed.