Skip to main content
FixMyTech

Passwords, Two-Factor Codes and Account Recovery

Two-factor authentication is the single most effective thing you can turn on, and also the most common way people lock themselves out of their own accounts permanently. The difference between those two outcomes is entirely about what you set up before anything goes wrong. These guides cover the setup that survives a lost phone, the recovery routes that still work when it is already too late, and how to tell which of your accounts is the one holding all the others up.

Accounts guides(14)

Where to Store Your Recovery Codes Safely

Recovery codes are the only guaranteed way back into a locked account. Here is where to keep them, and why the obvious places all fail at the moment you need them.

7 min read

How to Safely Share a Password With Family

Texting a password puts it in two message histories and two cloud backups forever. The better routes, and which accounts you should never share at all.

7 min read

How to See Every Device Signed Into Your Account

Find the device list on Google, Apple and Microsoft, work out which entries are genuinely suspicious, and revoke the access a password change leaves behind.

8 min read

What Passkeys Are and Whether to Switch

Passkeys replace the password with a key your device holds and a site cannot leak. Here is the mechanism, the lock-out risk, and how to keep a way back in.

8 min read

Authenticator App vs SMS Codes: Which to Use

SMS codes are the one second factor attackers defeat routinely. Here is the mechanism, what you give up by switching, and when SMS is still the right call.

7 min read

Topics in Accounts

Accounts questions

Which type of two-factor authentication is safest?
A hardware key or passkey, then an authenticator app, then SMS last. SMS codes can be intercepted by taking over your phone number, which is why it is the only form attackers routinely defeat at scale.
What happens to my codes if I lose my phone?
That depends entirely on whether you saved the recovery codes or enabled cloud backup when you set the app up. Without either, each account has to be recovered individually through its own support process, which can take weeks.
Are password managers safe?
Yes, and considerably safer than the alternative of reusing passwords. The vault is encrypted with a key derived from your master password, which the provider never receives, so a breach of their servers does not expose your passwords.

Security

Spot phishing before you click, check a device for malware, and know what to do in the first hour after a scam or a data breach.

20 guides

Google

Work out which service is eating your free 15GB, get Gmail sending again, and clear Google Photos without losing the pictures you want.

11 guides