DOORS Canada home
DOORS · Digital Skills

Two locks are better than one

A strong password is a good start. This lesson shows how another kind of proof adds a second lock, and introduces newer sign-in tools that can make security easier.

The trouble with one lock

A strong password is a good lock with one weakness: it works from anywhere. A stranger on the other side of the world who learns your password can walk right into your digital life, no travel required.

And passwords do get learned. Companies get hacked and lists of passwords leak out. Scam emails trick people into typing them. One lock isn't enough on its own.

The second lock

MFA stands for Multi-Factor Authentication, which is a long way of saying: the website asks for proof from at least two different corners of the Identity Triangle before letting anyone in.

Password plus a code from your phone is know plus have. Password plus a fingerprint is know plus are. The corners matter: two proofs from the same corner, like a password plus a secret question, is really one big lock with extra steps.

An authenticator app is another way to use the “have” corner. It creates a temporary code on your phone, usually even when you have no cellular service. When an account offers it, an authenticator app is generally safer than receiving codes by text.

Try it yourself below.

Your bank's login screen
Royal Raccoon Bank of Canada
jordan.h
Two corners confirmed. Access granted.
That is MFA. At least two different kinds of proof, and a stranger with only your password gets stopped at the second door. Turn it on first for your email, banking, health, government, and social-media accounts. When you have a choice, an authenticator app is generally safer than a texted code.

What the second lock actually stops

A stranger far away has learned your password from a leaked list. They type it in. The website asks for the second proof, a texted code, an authenticator code, or an approval on your device. Without that second proof, the stranger is stopped.

Meanwhile, you receive a code or approval request you did not start. That is not ordinary junk; it is a smoke alarm: someone may be trying to enter your account. Do not approve it or share the code. Open the real app or website yourself, review recent activity, and change your password if anything looks suspicious.

One rule about codes: only use a code after you started the login yourself on the real app or website. Never read a login code to a caller, send it in a message, or enter it through a link someone sent you. A second lock helps, but a scammer may still try to trick you into handing over the second key.

A newer lock: passkeys

Some websites now offer a passkey instead of a password. You sign in the same way you unlock your phone or computer: with your fingerprint, face, screen PIN, or device password.

A password is something you must remember. A passkey is something your device remembers for you. A passkey made for the real website will not work on a fake copy, which makes passkeys much harder for scammers to steal.

A passkey is stored on something you have, such as your phone or computer. Your face, fingerprint, or PIN unlocks it. You do not need to sort out which corner “counts”, the useful part is that your device and the real website do the security work together.

Next lesson

Locks keep strangers out, but what if you lose a key? Continue to The borrowed computer plan.

This mini-module