Why Passwords Are No Longer Enough

Passwords aren’t enough anymore. We’re seeing more phishing scams, inserted links and vulnerabilities than ever before. And we’ve also come up against even more hoops to get into our favorite apps.

Surely you’ve noticed all the times that you can’t login until you scour the house to find your phone and type in the code two seconds too late, and then have to start all over, questioning your reality and the feasibility of deleting all your online accounts….

Assuming you keep your online accounts, and your website, we’ll help you figure out what is going on, if it really is necessary, and how to secure your own website with proper Passwords/ Passkeys.

The two broad categories of extra security hoops that you’ve seen (in WordPress and everywhere else too) lately are these:

  • Two-Factor Authentication (2FA) – something you know and something you have
  • Passkeys (aka FIDO2) – something you are (fingerprint, face scan)

We’ll go over a few examples and show you what you need to do on your own website.

WordPress Two-Factor Authentication (2FA)

What is 2FA?

2FA stands for Two Factor Authentication. It means your password isn’t enough – you must add another step which drives us all mad. These include getting an SMS or email with a time-sensitive code, an authenticator app (with codes that change every 30 seconds) or push notifications (where you have to tap ‘yes’ on your phone).

Basically 2FA requires something you know (your password) and something you have (your phone).

So why do they force us to do such things? Passwords are just that easy to hack. And they’re not joking. I can guess most of your passwords just because I knew what one was years ago. (Yeah, I’m looking at YOU.) I think they’ve given up making us use long passwords with ! in place of i’s and @ in place of a’s. We are just a stubborn bunch and refuse to use random 16 character nonsense passwords.

Now, 2FA is the accepted standard. So to NOT do it, is not good for business. If you accept emails or money on your website, you need to add 2FA. (It is a simple plugin.)

Here’s a little review of the 2FA stuff, then we get to the good news!

Pros & Cons

ProsCons
Much safer than passwords aloneAdds one more step

Common 2FA Methods

These are commonly used – we will require your users (and you) to do the whole find-the-phone march just to login to your website. It’s necessary. Sorry, and you’re welcome.

MethodDescriptionProvided By
SMS CodeCode sent by textWebsite
Email CodeCode sent to your inboxWebsite
Authenticator AppTime-based code in your appWebsite + User App
Push NotificationTap to approve on your phoneWebsite + User App

Passwordless Authentication (Passkeys)

What is Passwordless Authentication?

This is the good news!! It isn’t available yet everywhere but it is on Google, Android, Windows and Apple – and it is a dream!

This is the strongest standard as it is based on nothing to know(or hack), nothing you have, only on who you are (biometrics). You can login to your websites and accounts, as easily as logging into your phone! Unlock your phone and you are automatically logged in!! So wherever you see a tiny link beneath a login that says “Enable authentication” or “Enable passkeys” – do it! There’s no downside! Well… unless you lose your phone.

If you haven’t secured your own devices yet, do that first.

Your phone must be locked and secure to use this method. And you must not share your device with anyone.

Anyone who can unlock your device (phone or computer) will
automatically have access to any passkey-enabled accounts.

Pros & Cons

ProsCons
No passwords to rememberNot supported everywhere (yet)
Resists phishing & password theftYou must protect the device itself
Fast logins via Face ID or fingerprintRequires secure device access

Common FIDO2 Methods

These are the commonly used methods, supported by the FIDO2 standard (passwordless types of security). If you’d like to try this on Google Workspace, here’s the tutorial.

MethodDescriptionProvided By
PasskeysLog in with Face ID, fingerprint, or PINWebsite + User Device
Magic LinkOne-time email link to log inWebsite
Biometric LoginUse face or fingerprint in appsUser Device
Security Key OnlyTap device, no password neededWebsite-Enabled Device (USB Key)

What to Do Now

  1. Use 2FA with a less grouchy manner (still working on that)
  2. Add login protection to your WordPress site (we can help with this).

To get 2FA on your website (which will be mandatory soon), we recommend using Login Lockdown. They use their own server resources so that your site doesn’t slow down at all. If you own an ecommerce or membership website this is very important. They also have a limited time offer for a “Life time Deal” – that means you pay once instead of a subscription – highly recommend!!

If you need a hand installing and configuring let us know. We can configure for one ticket or two if you want new login screens and recaptcha installed.

Questions? The chat is open!

New! Welcome-Email AI Agent

Optin-Welcome Series GPT

Cathy Mitchell

Single Mom, Volunteer, Lifelong Learner, Jesus Follower, Founder and CEO at WPBarista.