Passwords and authentication protect our email, mobile phone, bank account, social media, school portal and business website from unauthorized access.
A password is a secret that a user knows. Authentication is the complete process used by a system to check whether the person trying to log in is really the account owner.
For example, when you enter a password into your email account, the email service compares it with its stored login information. If the proof is correct, access is allowed.
What Is Authentication?
Authentication is the process of verifying the identity of a user, device or system.
In simple words, authentication asks:
“Can you prove that you are really the person you claim to be?”
According to NIST’s definition of authentication, a user proves their identity by controlling one or more authenticators, such as a password, phone, security key or biometric.
Real-Life Example
Imagine that you enter an office building.
- You tell the security guard your name.
- You show your employee ID card.
- The guard checks the card.
- You are allowed to enter only if the card is valid.
A computer system follows a similar process.
flowchart LR
A["Claim identity"] --> B["Provide proof"]
B --> C["System verifies proof"]
C --> D{"Proof correct?"}
D -->|Yes| E["Access allowed"]
D -->|No| F["Access denied"]
Practical Login Example
Suppose Ananya wants to open her email account:
- Her email address tells the system which account she wants to access.
- Her password provides proof that she owns the account.
- A verification code provides additional proof.
- The email service checks both proofs.
- Access is allowed only when the information is correct.
Identification, Authentication and Authorization
These three terms are related, but they do not mean the same thing.
| Process | Main question | Computer example | Office example |
|---|---|---|---|
| Identification | Who are you? | Entering a username | Telling the guard your name |
| Authentication | Can you prove it? | Entering a password or using a fingerprint | Showing an employee card |
| Authorization | What are you allowed to do? | Admin can edit; reader can only view | Employee can enter the office but not the server room |
Simple Example
A student enters a school portal using a username and password.
- The username identifies the student.
- The password authenticates the student.
- The student is authorized to view marks.
- The student is not authorized to change the marks.
Authentication proves identity, while authorization decides permissions.
What Is a Password?
A password is a secret combination of letters, numbers, spaces or symbols used to access an account, device or system.
A password is an example of “something you know.”
Passwords are commonly used to protect:
- Email accounts
- Social media accounts
- Online banking
- Mobile phones
- Computers and laptops
- Wi-Fi routers
- School and college portals
- WordPress websites
- Shopping accounts
- Cloud storage
Username and Password Example
Suppose a user has the following login details:
- Username:
student104 - Password: A private secret known only to the user
The username is normally not secret. It helps the system find the correct account. The password is secret and proves that the user is allowed to access that account.
Password, Passphrase and PIN
| Term | Meaning | Example format | Common use |
|---|---|---|---|
| Password | A secret containing characters | Random letters, numbers and symbols | Websites and apps |
| Passphrase | A longer password made from words | Several unrelated words | Email or password manager |
| PIN | A short numeric password | Four or six private digits | ATM, phone or device unlock |
Never use the example formats from an educational article as your real password.
Password Example
A password manager may generate a long random password containing letters, numbers and symbols. It is difficult to remember but also difficult to guess.
Passphrase Example
A memorable passphrase can be created using unrelated words:
Harbor Mango Ladder Violet Comet
This is only a format example—do not copy it.
The UK National Cyber Security Centre recommends combining random, unrelated words instead of using predictable personal information. Random words make a password longer while keeping it easier to remember. Read the NCSC guidance on random-word passwords.
PIN Example
An ATM commonly requires:
- Something you have: the bank card
- Something you know: the PIN
This is stronger than using a PIN alone because an attacker normally needs both the card and the PIN.
A short phone PIN can also be reasonably secure when it is checked locally by the phone, failed attempts are limited and the phone automatically locks. However, the same short PIN should not be used as an online account password.
Authentication Factors
An authentication factor is a type of proof used to verify identity. There are three main authentication factors.
flowchart TD
A["Authentication factors"]
A --> B["Something you know"]
A --> C["Something you have"]
A --> D["Something you are"]
B --> E["Password or PIN"]
C --> F["Phone, card or security key"]
D --> G["Fingerprint or face"]
1. Something You Know
This is information that should be known only to the user.
Examples include:
- Password
- Passphrase
- PIN
- Device unlock pattern
Real-life example: A customer enters a private PIN at an ATM.
2. Something You Have
This is a physical device or object controlled by the user.
Examples include:
- Mobile phone
- Bank card
- Smart card
- Authenticator device
- USB security key
- Hardware token
Real-life example: A bank sends a verification request to the customer’s registered phone.
3. Something You Are
This factor uses a physical or behavioural characteristic.
Examples include:
- Fingerprint
- Face
- Iris
- Voice
- Palm pattern
Real-life example: A person unlocks a phone using their fingerprint.
Biometrics are convenient, but they are not perfect. A fingerprint cannot be changed as easily as a password. Important devices should therefore have a secure PIN, recovery method and device encryption.
Single-Factor Authentication
Single-factor authentication uses only one type of proof.
Examples include:
- Password only
- PIN only
- Security card only
- Fingerprint only
Real-Life Example
A website asks only for a username and password. Anyone who steals the password may be able to access the account.
Single-factor authentication is easy to use, but it provides limited protection for important accounts.
What Is Two-Factor Authentication?
Two-factor authentication, or 2FA, requires two different types of authentication factors.
For example:
- Something you know: password
- Something you have: mobile phone
Even if a criminal steals the password, they still need the second factor.
flowchart TD
A["Enter username and password"] --> B{"Password correct?"}
B -->|No| C["Access denied"]
B -->|Yes| D["Verify phone, app or key"]
D --> E{"Second factor correct?"}
E -->|Yes| F["Access allowed"]
E -->|No| C
Important Difference
A password and a PIN are both something you know. Using both does not necessarily create true two-factor authentication.
However, a bank card and PIN use two different factors:
- Bank card: something you have
- PIN: something you know
That is a genuine two-factor combination.
What Is Multi-Factor Authentication?
Multi-factor authentication, or MFA, requires two or more different authentication factors.
The factors may include:
- Password plus authenticator app
- Password plus fingerprint
- Smart card plus PIN
- Security key plus device PIN
- Bank card plus PIN plus fingerprint
NIST defines MFA as authentication using more than one distinct factor type. Read the NIST explanation of multi-factor authentication.
2FA, 2SV and MFA
| Term | Meaning |
|---|---|
| 2FA | Exactly two different authentication factors |
| 2SV | Login completed in two verification steps |
| MFA | Two or more different authentication factors |
These terms are often used interchangeably by websites, but technically they can have slightly different meanings.
Common MFA Methods
SMS Verification Code
The service sends a one-time code to the registered mobile number.
Example: After entering a banking password, the customer receives a six-digit SMS code.
Advantages:
- Easy to understand
- Works on basic phones
- Better than using only a password
Limitations:
- A fake website can steal the code.
- A criminal may perform a SIM-swap attack.
- Messages may be intercepted or redirected.
- Mobile network problems can delay codes.
SMS authentication is better than password-only login, but stronger methods should be preferred when available.
Email Verification Code
A code or login link is sent to the registered email address.
Example: An online shopping website emails a code when it detects a login from a new laptop.
The protection depends heavily on the security of the email account. If a criminal already controls the email account, they may also receive the verification code.
Authenticator App
An authenticator app generates a temporary code, usually changing every few seconds.
Example: A WordPress administrator enters a password and then enters the current code from an authenticator app.
An authenticator app is generally safer than SMS because the code is generated on the device. However, the code can still be stolen through a convincing phishing website.
Push Notification
A login request appears in an authentication app. The user approves or denies it.
Example: An office employee enters a password on a laptop and receives an approval notification on a phone.
Users must never approve an unexpected request. Attackers sometimes send repeated requests until the user accepts one. This is called MFA fatigue or push bombing.
Number matching is safer because the app asks the user to enter or select a number displayed on the login screen.
Security Key
A security key is a physical device connected through USB, NFC or Bluetooth.
Example: An administrator inserts or taps a security key before entering the website’s admin panel.
Security keys using FIDO authentication are highly resistant to phishing because they verify the real website before completing authentication.
Passkey
A passkey is a modern replacement for a password. It uses cryptographic keys and is unlocked using the user’s device PIN, fingerprint, face or security key.
Passkeys are designed to resist phishing and credential stuffing. FIDO Alliance passkey guidance explains that passkeys use public-key cryptography and do not give the website a shared password that can be stolen.
How Does a Passkey Work?
When a passkey is created, two related cryptographic keys are produced:
- The public key is stored by the website.
- The private key remains protected on the user’s device, password manager or security key.
During login, the website sends a unique challenge. The device signs it with the private key, and the website checks the result using the public key.
sequenceDiagram
participant U as User
participant D as User device
participant W as Website
U->>W: Choose sign in with passkey
W->>D: Send unique challenge
D->>U: Request PIN, face or fingerprint
U->>D: Approve sign-in
D->>W: Return signed challenge
W->>W: Verify with public key
W-->>U: Allow access
The user does not type the private key. A fake website cannot simply ask the user to reveal it.
For passkey-based login, biometric information normally stays on the user’s device. The website receives confirmation that local verification succeeded, not the user’s fingerprint or face image. See FIDO’s technical explanation of passkeys.
Password Authentication vs Passkeys
| Feature | Password | Passkey |
|---|---|---|
| User remembers a secret | Yes | No |
| Secret typed into website | Yes | No |
| Can be reused | Unfortunately, yes | Unique to each service |
| Vulnerable to ordinary phishing | Yes | Designed to resist phishing |
| Website stores password-related data | Password hash | Public key |
| Login method | Type the password | Unlock device or security key |
| Credential stuffing risk | High if password is reused | Greatly reduced |
Passkeys are not available on every website yet. Where passkeys are unavailable, use a strong unique password with MFA.
How to Create a Strong Password
A strong password should be:
- Long
- Unique
- Difficult to guess
- Unrelated to personal information
- Randomly generated where possible
CISA recommends strong passwords that are long, random and unique. Its user guidance commonly recommends at least 16 characters.
Weak Password Examples
The following patterns are weak:
password123qwerty123- A person’s name followed by a birth year
- A mobile number
- A pet’s name
- A favourite sports team
- A website name followed by
123 - Simple keyboard patterns
- The same password used on every account
Why Personal Information Is Dangerous
A criminal may find the following information on social media:
- Name
- Date of birth
- School name
- Pet’s name
- Favourite team
- Family members
- City
- Workplace
If this information is used in a password, the password may be easier to guess.
Symbols Do Not Automatically Make a Password Strong
Changing password to P@ssw0rd! does not make it truly unpredictable. Attackers know common substitutions such as:
areplaced with@oreplaced with0ireplaced with1- Adding
123at the end - Adding the current year
Length and uniqueness usually provide more practical protection than predictable substitutions.
Why Every Account Needs a Unique Password
Password reuse means using the same password on multiple websites.
Suppose Rohan uses the same password for:
- Shopping
- Social media
- School portal
If the shopping website suffers a data breach, criminals may try the stolen email and password on all the other services. This attack is called credential stuffing.
A unique password stops one breached website from automatically exposing every other account.
Protect the Email Account First
The email account is especially important because password-reset messages for other accounts usually arrive there.
If an attacker controls your email, they may reset the passwords of your:
- Social media accounts
- Shopping accounts
- Cloud storage
- School portal
- Business website
- Financial services
Use a unique password and strong MFA or a passkey on your primary email account.
What Is a Password Manager?
A password manager is an application that securely stores and generates passwords.
Instead of remembering 50 different passwords, the user remembers one strong master password and lets the manager handle the others.
Practical Example
Neha has accounts on 40 websites.
Without a password manager, she may reuse three or four passwords. With a password manager, every account can have a separate random password.
The password manager can:
- Generate long random passwords
- Store usernames and passwords
- Autofill login forms
- Warn about reused passwords
- Warn about weak or exposed passwords
- Synchronize credentials across trusted devices
- Store passkeys and recovery information
Password Manager Safety Tips
- Use a long and unique master password.
- Turn on MFA for the password manager.
- Keep recovery information secure.
- Install updates regularly.
- Lock the manager when the device is unattended.
- Never share the master password.
- Download the manager only from its official source.
A password manager’s autofill feature can also help detect phishing. If it refuses to fill a saved password, check whether the website address is correct.
Common Password and Authentication Attacks
| Attack | How it works | Real-life example | Main protection |
|---|---|---|---|
| Brute-force attack | Tries many possible passwords | Automated software repeatedly attacks one account | Long password, rate limiting and MFA |
| Dictionary attack | Tries common words and password lists | Attacker tries welcome, football and common variations | Random password or passphrase |
| Credential stuffing | Uses credentials stolen from another service | A leaked shopping password is tried on an email account | Unique password and MFA |
| Password spraying | Tries one common password on many accounts | Welcome123 is tested against hundreds of employees | Block weak passwords and use MFA |
| Phishing | Uses a fake login page | Fake bank message asks the user to “verify” the account | Check the URL and use passkeys |
| Keylogging | Malware records keyboard input | Malicious software captures a typed password | Updated security software and clean devices |
| Shoulder surfing | Someone watches the user type | A person observes an ATM PIN | Cover the keypad and protect the screen |
| Social engineering | Attacker manipulates the victim | Fake IT support asks for a password or OTP | Verify the caller and never share secrets |
| SIM swapping | Phone number is transferred to attacker’s SIM | Criminal receives the victim’s banking code | Prefer authenticator apps or security keys |
| MFA fatigue | Repeated approval requests pressure the user | Employee approves a fake request to stop notifications | Deny unexpected requests and report them |
| Session theft | An attacker steals an authenticated session | Malware steals a browser cookie after login | Secure devices and sign out active sessions |
OWASP provides additional explanations of credential stuffing, password spraying and related defences.
Authentication Methods Compared
| Method | Convenience | Relative protection | Important limitation |
|---|---|---|---|
| Password only | High | Basic | Can be guessed, stolen or reused |
| Password plus email code | Medium | Better than password only | Email account may be compromised |
| Password plus SMS | Medium | Better | Vulnerable to phishing and SIM swapping |
| Authenticator app code | Medium | Stronger | Code can still be phished |
| Push approval | High | Stronger | Vulnerable to MFA fatigue |
| Fingerprint or face | High | Strong on a protected device | Requires secure backup method |
| FIDO security key | Medium | Very strong | Physical key can be lost |
| Passkey | High | Very strong | Not supported by every service |
The exact protection depends on how each service implements the method.
Real-Life Authentication Examples
1. ATM
- Card identifies the bank account.
- PIN authenticates the customer.
- The bank checks the card and PIN.
- The customer is authorized to withdraw only within the permitted limit.
2. Mobile Phone
- The device belongs to the user.
- A PIN, fingerprint or face unlocks it.
- After several failed attempts, the phone may delay or block further attempts.
3. Online Banking
- Customer ID identifies the account.
- Password provides the first proof.
- Banking app, OTP or card reader provides additional proof.
- A separate confirmation may be required for a large payment.
4. Email Account
- Email address identifies the user.
- Password authenticates the user.
- A passkey, security key or authenticator app adds stronger protection.
- A new-device notification helps detect suspicious login attempts.
5. Office Computer
- Employee enters a company username and password.
- An authentication app asks for approval.
- Access is allowed only to files permitted for that employee’s role.
6. School Portal
- Student ID identifies the student.
- Password verifies identity.
- Students can view their results.
- Teachers may enter marks.
- Administrators can manage accounts.
7. Shopping Website
- The customer logs in with a password or passkey.
- A payment provider may request additional authentication.
- A password reset link is sent to the registered email.
8. Shared Family Computer
Every person should have a separate user account. This prevents one user from automatically accessing another person’s:
- Files
- Browser history
- Saved passwords
- Personal settings
9. Wi-Fi Router
The router’s administrator password should be changed from the default value. Otherwise, anyone who knows the manufacturer’s default credentials may change network settings.
The Wi-Fi password and router administration password should also be different.
10. WordPress Website
A WordPress website owner should use:
- A unique administrator password
- 2FA or a passkey where supported
- Separate administrator, editor and author accounts
- Minimum necessary permissions
- Login rate limiting
- HTTPS
- Updated WordPress software, themes and plugins
- Secure backups
- Login activity monitoring
The email connected to the administrator account must also be strongly protected because it can usually reset the WordPress password.
Safe Account Recovery
Account recovery helps users regain access when they forget a password or lose an authentication device. However, a weak recovery process can become the easiest way for an attacker to enter an account.
Recovery Methods
Common recovery options include:
- Recovery email
- Registered phone
- Backup security key
- Recovery codes
- Trusted device
- Identity verification through the service provider
Recovery Code Example
When 2FA is enabled, a website may provide several one-time recovery codes. These codes can be used if the phone or authentication device is lost.
Recovery codes should be:
- Stored in a safe offline location
- Kept separate from the main device
- Used only on the real website
- Never sent through chat or email to strangers
- Replaced if someone else sees them
Avoid relying on personal security questions such as a pet’s name. Answers may be guessed or found on social media.
What Should You Do If a Password Is Stolen?
Act immediately.
- Open the real website or official app directly.
- Change the compromised password.
- Change the same password anywhere else it was reused.
- Secure the associated email account.
- Sign out of all other sessions.
- Turn on MFA or create a passkey.
- Check recovery email addresses and phone numbers.
- Remove unknown devices and connected applications.
- Check email forwarding rules.
- Scan the device for malware.
- Contact the bank immediately if money is involved.
- Inform workplace IT if it is a company account.
Do not change important passwords from a device that may still contain malware.
Password Rules for Website Owners
Website owners must protect passwords on the server as well as on the login page.
Current NIST password guidance recommends that service providers:
- Require at least 15 characters when a password is the only authentication factor.
- Permit at least 64 characters as the maximum supported length.
- Allow password managers, autofill and paste.
- Compare new passwords with lists of common or compromised passwords.
- Limit repeated failed login attempts.
- Avoid unnecessary password-composition rules.
- Avoid forced periodic password changes unless compromise is suspected.
- Avoid knowledge-based security questions.
- Store passwords using salted, secure password hashing.
- Never store passwords as readable plain text.
These are service-provider requirements and recommendations. Individual users should still follow the simpler rule: create a long, unique password for every account and turn on strong MFA.
Why Passwords Must Be Hashed
A responsible website should not store the original readable password.
flowchart LR
A["User creates password"] --> B["Website adds unique salt"]
B --> C["Slow password hashing"]
C --> D["Store hash, not password"]
During login, the website hashes the entered password again and compares the result. If the database is stolen, hashing makes password recovery more difficult for the attacker. It does not make weak passwords safe, so long and unique passwords are still necessary.
Essential Authentication Safety Rules
- Never share a password, PIN, OTP or recovery code.
- Use a different password for every account.
- Protect your email account first.
- Use at least 16 characters when possible.
- Use a password manager.
- Enable MFA on important accounts.
- Prefer a passkey or security key where available.
- Deny unexpected login approvals.
- Check the website address before entering credentials.
- Do not save passwords on public computers.
- Sign out after using a shared device.
- Keep devices, browsers and applications updated.
- Review active sessions and connected devices.
- Change a password immediately when compromise is suspected.
Frequently Asked Questions
Is a long password better than a complex password?
A long, unique and unpredictable password is generally more useful than a short password containing predictable symbol substitutions. Length should be combined with uniqueness.
Is it safe to use the same strong password everywhere?
No. If one website is breached, the stolen password may be tried on other accounts.
Should I change my password every month?
Not automatically. Modern NIST guidance advises services against forcing periodic changes without evidence of compromise. Change the password if it has been exposed, reused, shared or stolen.
Is SMS 2FA useless?
No. SMS 2FA is better than password-only authentication, but authenticator apps, security keys and passkeys generally provide stronger protection.
Can I share an OTP with bank support?
No. Never share an OTP, PIN, password or recovery code. A legitimate employee should not need your secret code.
Are fingerprints safer than passwords?
Fingerprints are convenient and can be strong when used securely on a protected device. However, a fingerprint cannot be changed like a password, so a secure PIN and recovery process are also required.
Is a passkey the same as a password?
No. A password is a secret that the user types. A passkey uses cryptographic keys and is normally unlocked through the user’s device.
What is the best authentication method?
For services that support it, a passkey or FIDO security key provides strong phishing-resistant authentication. Otherwise, use a unique password with MFA.
Conclusion
A password is only one part of account security. Authentication is the complete process through which a system verifies identity.
For better protection:
- Create long and unique passwords.
- Store them in a password manager.
- Enable MFA on email, banking, social media and website accounts.
- Prefer passkeys or security keys when available.
- Never share passwords, OTPs or recovery codes.
- Protect account-recovery methods carefully.
Think of authentication like the security system of a building. A password is one lock, but MFA adds another locked door, and a passkey uses a lock designed to work only with the correct building.
