Use passkey, webauth, like with Yubikey or similar, this will make you password leak unusable. Of course you must have unique password and use a password manager to generate and enter strong and long password.

All these services support passkey and webauth. It's the only phishing-proof, easy to use, privacy friendly 2FA.

Reply to this note

Please Login to reply.

Discussion

Thanks 💜

What happens if one loses the yubikey?

You have ways to restore access, like with a second Yubikey, or a sheet of 10 uniques codes or another 2FA (but make sure to not make the weak link) or even a 3FA sometimes (psw+ phone code + email/backup email for email, or phone app 2FA...).

Thanks for the breakdown ⚡️💜