Blog

Password security levels explained: From weak passwords to MFA and passkeys

A guide to passwords, 2FA, authenticator apps, and passkeys — and which level is right for which account.

Guillaume Pascuale headshot

Guillaume Pascual

October 09, 2026

Woman practising 2-factor authentication using a mobile phone and laptop.

Quick answer:
Password security works in levels, not all-or-nothing. A unique password from a password manager is the baseline. Adding two-factor authentication (2FA), ideally through an authenticator app rather than a text message, adds significantly more protection. Authenticator apps block over 99% of account-takeover attempts. Passkeys are the strongest option available today because there's no password left for a scammer to steal in the first place.

Most people think about passwords as one setting: either they have one, or they don't. In practice, account security works more like a ladder — each rung adds real protection, and most people are standing lower on it than they realize.

Microsoft's Digital Defense Report found that 97% of the identity attacks it observed were password spray attacks. Spray attacks use automated tools trying common or reused passwords across huge numbers of accounts. These are not sophisticated hacking attacks. That number explains why password habits matter: most break-ins aren't clever, they're just patient.

Every step up the ladder — a password manager, 2FA, authenticator app, passkey — removes a specific step scammers use to get in. You don't need the top rung on every account, but you should know what each one buys you.

The 5 levels of password security

Here's the ladder in order, from what most people are still doing to what security experts now recommend for anything sensitive.

LevelWhat it looks likeHow strong it isEffort to use
1. Simple passwordOne easy-to-remember word or phrase, often reused across sitesWeak — crackable in seconds, and one leak exposes every account using itLowest
2. Strong, unique passwordLong, random password, different for every account, stored in a password managerGood — resists cracking and contains damage from any single leakLow, once set up
3. SMS 2FAPassword plus a one-time code texted to your phoneBetter — blocks most automated attacks, but vulnerable to SIM-swap fraudLow
4. Authenticator appPassword plus a rotating code generated in an app like Authy or Google AuthenticatorStrong — codes never travel over the phone network, so SIM-swap attacks don't workModerate
5. PasskeysYour device's fingerprint, face, or PIN unlocks a cryptographic key — no password typed at allStrongest — phishing-resistant by design; there's no password or code for a scammer to stealLowest, once enabled

Level 1: The simple, reused password

This is where most people start: a password that's easy to remember, often reused across banking, email, and shopping accounts because keeping track of dozens of different ones feels unmanageable.

The problem is that reuse turns one leak into many. If a single retail site is breached and your password leaks, attackers immediately try that same password on your email and bank accounts — a technique called credential stuffing that works precisely because so many people reuse passwords.

Level 2: A strong, unique password — managed, not memorized

The average person now manages around 301 passwords. No one can memorize that many strong, unique passwords.

Password managers generate long, random passwords for every account and fill them in automatically, so the only thing you need to remember is one master password.

This single change closes the credential-stuffing gap almost entirely, since a leak on one site no longer says anything about your password anywhere else.

Level 3: Two-factor authentication (2FA) by text message

2FA adds a second step after your password: a one-time code, most commonly sent by text message.

It's a real improvement — it stops most automated attacks cold — but it's also the weakest form of 2FA.

SMS codes can be intercepted through SIM-swap fraud, where a scammer convinces your mobile carrier to move your phone number onto a device they control.

It's still far better than a password alone, just not the strongest option available.

Level 4: Authenticator apps

An authenticator app — Google Authenticator, Microsoft Authenticator, Authy, or the one built into your password manager — generates a rotating code directly on your device instead of sending it over text.

Because the code never travels over the phone network, SIM-swap attacks don't work against it.

Microsoft's research shows that turning on MFA, in any form, blocks more than 99% of password-related attacks; authenticator apps get you that protection without the SMS weak point.

Level 5: Passkeys

Passkeys remove the password from the equation entirely.

Your device — phone, laptop, tablet — uses your fingerprint, face, or PIN to unlock a cryptographic key that's unique to that device and that account.

There's no password to type, guess, or phish, and no code to intercept.

Adoption has moved fast: more than 1 billion people have activated at least one passkey, and Google alone has moved over 800 million accounts onto them.

Passkeys sign you in roughly 8 times faster than a password-plus-MFA combination, and succeed on the first try far more often — security and convenience improving together, which is rare in this space.

Sources: Microsoft Digital Defense Report 2025; FIDO Alliance State of Passkeys 2026; Dashlane 2026 authentication data; Descope 2026 customer authentication research.

Which level should you use?

Everyday accounts (shopping, streaming, forums)

A unique password from a password manager is enough. Add an authenticator app if the site offers it — most now do.

Email, banking, and anything tied to money

Use an authenticator app at minimum, and switch to a passkey the moment the provider supports it.

Email in particular deserves your strongest available protection, since it's usually the account a scammer can use to reset every other password you own.

Accounts you can enable passkeys on today

Google, Apple, Microsoft, and a fast-growing list of banks and retailers already support passkeys.

If you see the option, it's worth the two minutes to turn it on — it's both stronger and easier to use than what it replaces.

Where Webroot Total Protection fits in

Remembering which accounts have 2FA, which have passkeys, and which still need attention is exactly the kind of ongoing maintenance most people don't have time for.

A built-in password manager handles generating and storing passwords automatically, and pairing it with identity and dark-web monitoring means you find out if a password has leaked before it's used against you rather than after.

Frequently asked questions

Is SMS two-factor authentication still worth using?

Yes, if it's the only option a site offers it's far better than a password alone. But switch to an authenticator app or passkey wherever the account allows it, since SMS codes can be intercepted through SIM-swap fraud.

Do I need a password manager if I already use 2FA?

Yes. 2FA protects the login step, but a weak or reused password is still the first thing attackers try, and a password manager is what makes strong, unique passwords realistic to maintain across dozens of accounts.

Are passkeys actually safe, or just convenient?

Both. Passkeys are phishing-resistant by design, since there's no password or code for a scammer to trick you into revealing. The convenience and the security improvement come from the same design choice.

What's the single biggest password mistake people make?

Reusing the same password across multiple accounts. It turns one data breach, anywhere, into access to everything else that shares that password.

Guillaume Pascuale headshot

Guillaume Pascual

Guillaume Pascual leads product marketing for Webroot’s consumer cybersecurity portfolio at OpenText. With more than two decades in tech—including roles at Apple, Microsoft, Norton—he focuses on translating complex security topics into strategies that matter for real people.