NotesEveryday tech
Passwords, passkeys and two-factor: a sensible setup for a small business or a household
What Canada's cyber security agency and the current US standard actually recommend, reduced to a setup you can finish in an afternoon.
Most account security advice is either too vague to act on ("use strong passwords") or too long to finish. This note takes what two serious sources say, the Canadian Centre for Cyber Security and the US National Institute of Standards and Technology (NIST), and turns it into a setup for a small business or a household. Where the two disagree, it says so.
Start with the accounts that unlock the others
Before changing anything, list the accounts that can reset other accounts. For most people that is:
- the main email account, because almost every "forgot password" link goes there;
- the phone account and the Apple, Google or Microsoft account the phone signs in to;
- banking and any account that holds money, such as a payment processor;
- the password manager, if you use one;
- for a business, the domain registrar and the account that runs the website.
Secure these first, in that order. An attacker who holds your email can usually take most of the rest.
Passwords: long beats complicated
The Cyber Centre's guidance is concrete:
- a passphrase should be at least four words and 15 characters long;
- a password should be at least 12 characters;
- use a different password, passphrase or PIN for every account and device.
NIST's current guideline, SP 800-63B-4, points the same way from the service's side. A password used on its own must be at least 15 characters. Services should not impose composition rules, such as demanding a mix of symbols and capitals, and should not force people to change passwords on a schedule. A change should be forced only when there is evidence the password has been compromised.
The lesson for a household: stop rotating passwords every few months and stop inventing clever substitutions. Make each one long and unique, and change it when a service tells you it may have leaked.
Password managers, and where the two sources differ
Nobody remembers dozens of long, unique passwords. A password manager remembers them for you and fills them in only on the site they belong to.
Here the sources part slightly. NIST requires services to allow password managers and autofill. The Cyber Centre suggests a manager for lower-sensitivity accounts, but not for sensitive ones, giving administrator and banking accounts as examples, and says to protect the manager itself with a strong passphrase and multi-factor authentication.
A reasonable middle path: use a manager for everything routine, protect it with a long passphrase and a second factor, and keep the handful of most sensitive credentials, such as banking, as passphrases you actually know.
Two-factor: not all second factors are equal
Multi-factor authentication (MFA) means proving who you are with more than one kind of evidence. Get Cyber Safe describes the kinds as something you know, something you have and something that is part of you. Turning it on means a stolen password is no longer enough.
The Cyber Centre ranks the options clearly in its guidance on deploying MFA:
- FIDO-based methods, meaning security keys and passkeys, are "strongly recommended".
- SMS codes should be considered only for low-risk logins, because the codes travel unencrypted and can be intercepted, for example through SIM swapping or phishing.
- Watch for MFA fatigue, where an attacker triggers approval prompts again and again until someone taps "approve" to make them stop. Never approve a sign-in you did not start.
In practice, from strongest to weakest: a passkey or physical security key, then an authenticator app, then a text message. A text message is still far better than nothing.
Passkeys, briefly
A passkey replaces the password with a pair of cryptographic keys. The website stores only the public key; the private key stays with you and is unlocked by your device's fingerprint, face or PIN. The FIDO Alliance, which maintains the standard, describes passkeys as phishing-resistant: each one is tied to the website it was made for, so it will not work on a lookalike site, and there is no password on the server to steal. The biometric check happens on your device and is never sent to the site.
There are two kinds:
- synced passkeys are copied across your devices by your platform account or password manager, which makes them convenient and recoverable;
- device-bound passkeys live on a single piece of hardware, such as a security key, and never leave it.
The Cyber Centre's guidance on passkeys stresses keeping the private keys secure. With synced passkeys, that means the account doing the syncing becomes one of the most important you have, so give it the strongest protection available.
Where a service offers a passkey, use it. Where it does not, use a long unique password plus the strongest second factor it supports.
Plan for losing your phone
Every setup above assumes you can still reach your second factor. Plan for the day you cannot.
- Recovery codes. Many services issue one-time recovery codes when you turn on MFA. NIST's guidance describes saved recovery codes as meant to be kept offline, printed or written down, and stored securely. Put them with your important papers, not in the same phone you are protecting.
- A backup factor. The Cyber Centre advises giving users a backup factor as strong as the primary one. A second security key, kept at home, is the cleanest version.
- For a business, make sure at least two trusted people can recover the email, domain and banking accounts, so one lost phone does not lock the business out.
The afternoon version
- List the accounts that unlock the others.
- Install a password manager and protect it with a long passphrase and MFA.
- Give each key account a long, unique password or passphrase.
- Turn on the strongest second factor each one offers, and a passkey where available.
- Save the recovery codes offline, somewhere safe.
- Set up a backup factor, and for a business, a second person who can recover access.
Drafted with AI assistance.
Sources
- Canadian Centre for Cyber Security — Best practices for passphrases and passwords (ITSAP.30.032) cyber.gc.ca
- Canadian Centre for Cyber Security — Steps for effectively deploying multi-factor authentication (ITSAP.00.105) cyber.gc.ca
- Canadian Centre for Cyber Security — Cyber security considerations for passkeys (ITSAP.30.033) cyber.gc.ca
- Get Cyber Safe (Government of Canada) — Multi-factor authentication getcybersafe.gc.ca
- FIDO Alliance — Passkeys fidoalliance.org
- NIST — SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management pages.nist.gov