Password security levels explained: From weak passwords to MFA and passkeys
A guide to passwords, 2FA, authenticator apps, and passkeys — and which level is right for which account.
Guillaume Pascual
October 09, 2026

Quick answer:
Password security works in levels, not all-or-nothing. A unique password from a password manager is the baseline. Adding two-factor authentication (2FA), ideally through an authenticator app rather than a text message, adds significantly more protection. Authenticator apps block over 99% of account-takeover attempts. Passkeys are the strongest option available today because there's no password left for a scammer to steal in the first place.
Most people think about passwords as one setting: either they have one, or they don't. In practice, account security works more like a ladder — each rung adds real protection, and most people are standing lower on it than they realize.
Microsoft's Digital Defense Report found that 97% of the identity attacks it observed were password spray attacks. Spray attacks use automated tools trying common or reused passwords across huge numbers of accounts. These are not sophisticated hacking attacks. That number explains why password habits matter: most break-ins aren't clever, they're just patient.
Every step up the ladder — a password manager, 2FA, authenticator app, passkey — removes a specific step scammers use to get in. You don't need the top rung on every account, but you should know what each one buys you.
The 5 levels of password security
Here's the ladder in order, from what most people are still doing to what security experts now recommend for anything sensitive.
| Level | What it looks like | How strong it is | Effort to use |
|---|---|---|---|
| 1. Simple password | One easy-to-remember word or phrase, often reused across sites | Weak — crackable in seconds, and one leak exposes every account using it | Lowest |
| 2. Strong, unique password | Long, random password, different for every account, stored in a password manager | Good — resists cracking and contains damage from any single leak | Low, once set up |
| 3. SMS 2FA | Password plus a one-time code texted to your phone | Better — blocks most automated attacks, but vulnerable to SIM-swap fraud | Low |
| 4. Authenticator app | Password plus a rotating code generated in an app like Authy or Google Authenticator | Strong — codes never travel over the phone network, so SIM-swap attacks don't work | Moderate |
| 5. Passkeys | Your device's fingerprint, face, or PIN unlocks a cryptographic key — no password typed at all | Strongest — phishing-resistant by design; there's no password or code for a scammer to steal | Lowest, once enabled |
Level 1: The simple, reused password
This is where most people start: a password that's easy to remember, often reused across banking, email, and shopping accounts because keeping track of dozens of different ones feels unmanageable.
The problem is that reuse turns one leak into many. If a single retail site is breached and your password leaks, attackers immediately try that same password on your email and bank accounts — a technique called credential stuffing that works precisely because so many people reuse passwords.
Level 2: A strong, unique password — managed, not memorized
The average person now manages around 301 passwords. No one can memorize that many strong, unique passwords.
Password managers generate long, random passwords for every account and fill them in automatically, so the only thing you need to remember is one master password.
This single change closes the credential-stuffing gap almost entirely, since a leak on one site no longer says anything about your password anywhere else.
Level 3: Two-factor authentication (2FA) by text message
2FA adds a second step after your password: a one-time code, most commonly sent by text message.
It's a real improvement — it stops most automated attacks cold — but it's also the weakest form of 2FA.
SMS codes can be intercepted through SIM-swap fraud, where a scammer convinces your mobile carrier to move your phone number onto a device they control.
It's still far better than a password alone, just not the strongest option available.
Level 4: Authenticator apps
An authenticator app — Google Authenticator, Microsoft Authenticator, Authy, or the one built into your password manager — generates a rotating code directly on your device instead of sending it over text.
Because the code never travels over the phone network, SIM-swap attacks don't work against it.
Microsoft's research shows that turning on MFA, in any form, blocks more than 99% of password-related attacks; authenticator apps get you that protection without the SMS weak point.
Level 5: Passkeys
Passkeys remove the password from the equation entirely.
Your device — phone, laptop, tablet — uses your fingerprint, face, or PIN to unlock a cryptographic key that's unique to that device and that account.
There's no password to type, guess, or phish, and no code to intercept.
Adoption has moved fast: more than 1 billion people have activated at least one passkey, and Google alone has moved over 800 million accounts onto them.
Passkeys sign you in roughly 8 times faster than a password-plus-MFA combination, and succeed on the first try far more often — security and convenience improving together, which is rare in this space.
Sources: Microsoft Digital Defense Report 2025; FIDO Alliance State of Passkeys 2026; Dashlane 2026 authentication data; Descope 2026 customer authentication research.
Which level should you use?
Everyday accounts (shopping, streaming, forums)
A unique password from a password manager is enough. Add an authenticator app if the site offers it — most now do.
Email, banking, and anything tied to money
Use an authenticator app at minimum, and switch to a passkey the moment the provider supports it.
Email in particular deserves your strongest available protection, since it's usually the account a scammer can use to reset every other password you own.
Accounts you can enable passkeys on today
Google, Apple, Microsoft, and a fast-growing list of banks and retailers already support passkeys.
If you see the option, it's worth the two minutes to turn it on — it's both stronger and easier to use than what it replaces.
Where Webroot Total Protection fits in
Remembering which accounts have 2FA, which have passkeys, and which still need attention is exactly the kind of ongoing maintenance most people don't have time for.
A built-in password manager handles generating and storing passwords automatically, and pairing it with identity and dark-web monitoring means you find out if a password has leaked before it's used against you rather than after.
Frequently asked questions
Is SMS two-factor authentication still worth using?
Yes, if it's the only option a site offers it's far better than a password alone. But switch to an authenticator app or passkey wherever the account allows it, since SMS codes can be intercepted through SIM-swap fraud.
Do I need a password manager if I already use 2FA?
Yes. 2FA protects the login step, but a weak or reused password is still the first thing attackers try, and a password manager is what makes strong, unique passwords realistic to maintain across dozens of accounts.
Are passkeys actually safe, or just convenient?
Both. Passkeys are phishing-resistant by design, since there's no password or code for a scammer to trick you into revealing. The convenience and the security improvement come from the same design choice.
What's the single biggest password mistake people make?
Reusing the same password across multiple accounts. It turns one data breach, anywhere, into access to everything else that shares that password.

Guillaume Pascual
Guillaume Pascual leads product marketing for Webroot’s consumer cybersecurity portfolio at OpenText. With more than two decades in tech—including roles at Apple, Microsoft, Norton—he focuses on translating complex security topics into strategies that matter for real people.