Why Passwords Are No Longer Enough
Passwords aren’t enough anymore. We’re seeing more phishing scams, inserted links and vulnerabilities than ever before. And we’ve also come up against even more hoops to get into our favorite apps.
Surely you’ve noticed all the times that you can’t login until you scour the house to find your phone and type in the code two seconds too late, and then have to start all over, questioning your reality and the feasibility of deleting all your online accounts….
Assuming you keep your online accounts, and your website, we’ll help you figure out what is going on, if it really is necessary, and how to secure your own website with proper Passwords/ Passkeys.
The two broad categories of extra security hoops that you’ve seen (in WordPress and everywhere else too) lately are these:
- Two-Factor Authentication (2FA) – something you know and something you have
- Passkeys (aka FIDO2) – something you are (fingerprint, face scan)
We’ll go over a few examples and show you what you need to do on your own website.
WordPress Two-Factor Authentication (2FA)
What is 2FA?
2FA stands for Two Factor Authentication. It means your password isn’t enough – you must add another step which drives us all mad. These include getting an SMS or email with a time-sensitive code, an authenticator app (with codes that change every 30 seconds) or push notifications (where you have to tap ‘yes’ on your phone).
Basically 2FA requires something you know (your password) and something you have (your phone).
So why do they force us to do such things? Passwords are just that easy to hack. And they’re not joking. I can guess most of your passwords just because I knew what one was years ago. (Yeah, I’m looking at YOU.) I think they’ve given up making us use long passwords with ! in place of i’s and @ in place of a’s. We are just a stubborn bunch and refuse to use random 16 character nonsense passwords.
Now, 2FA is the accepted standard. So to NOT do it, is not good for business. If you accept emails or money on your website, you need to add 2FA. (It is a simple plugin.)
Here’s a little review of the 2FA stuff, then we get to the good news!
Pros & Cons
| Pros | Cons |
|---|---|
| Much safer than passwords alone | Adds one more step |
Common 2FA Methods
These are commonly used – we will require your users (and you) to do the whole find-the-phone march just to login to your website. It’s necessary. Sorry, and you’re welcome.
| Method | Description | Provided By |
|---|---|---|
| SMS Code | Code sent by text | Website |
| Email Code | Code sent to your inbox | Website |
| Authenticator App | Time-based code in your app | Website + User App |
| Push Notification | Tap to approve on your phone | Website + User App |
Passwordless Authentication (Passkeys)
What is Passwordless Authentication?
This is the good news!! It isn’t available yet everywhere but it is on Google, Android, Windows and Apple – and it is a dream!
This is the strongest standard as it is based on nothing to know(or hack), nothing you have, only on who you are (biometrics). You can login to your websites and accounts, as easily as logging into your phone! Unlock your phone and you are automatically logged in!! So wherever you see a tiny link beneath a login that says “Enable authentication” or “Enable passkeys” – do it! There’s no downside! Well… unless you lose your phone.
If you haven’t secured your own devices yet, do that first.
Your phone must be locked and secure to use this method. And you must not share your device with anyone.
Pros & Cons
| Pros | Cons |
|---|---|
| No passwords to remember | Not supported everywhere (yet) |
| Resists phishing & password theft | You must protect the device itself |
| Fast logins via Face ID or fingerprint | Requires secure device access |
Common FIDO2 Methods
These are the commonly used methods, supported by the FIDO2 standard (passwordless types of security). If you’d like to try this on Google Workspace, here’s the tutorial.
| Method | Description | Provided By |
|---|---|---|
| Passkeys | Log in with Face ID, fingerprint, or PIN | Website + User Device |
| Magic Link | One-time email link to log in | Website |
| Biometric Login | Use face or fingerprint in apps | User Device |
| Security Key Only | Tap device, no password needed | Website-Enabled Device (USB Key) |
What to Do Now
- Use 2FA with a less grouchy manner (still working on that)
- Add login protection to your WordPress site (we can help with this).

To get 2FA on your website (which will be mandatory soon), we recommend using Login Lockdown. They use their own server resources so that your site doesn’t slow down at all. If you own an ecommerce or membership website this is very important. They also have a limited time offer for a “Life time Deal” – that means you pay once instead of a subscription – highly recommend!!
If you need a hand installing and configuring let us know. We can configure for one ticket or two if you want new login screens and recaptcha installed.
Questions? The chat is open!
New! Welcome-Email AI Agent
Looking at email marketing? Don’t forget a welcome series – folks are 4x more likely to open the first email than any other email that you send! Enter your email and we’ll send you to our custom AI Agent that will help you craft five highly converting emails in a welcome series! Then see this post for the tutorial.

Cathy Mitchell
Single Mom, Volunteer, Lifelong Learner, Jesus Follower, Founder and CEO at WPBarista.
