15.1 Passkeys wherever they are available
When your important services offer a passkey, use it. Passkeys rely on cryptographic authentication bound to the specific service, which makes them resistant to many classic forms of phishing.
15.2 Physical security keys
For particularly sensitive accounts, some platforms let you use a FIDO-compatible physical key.
password / username
+
physical key
+
Touch ID / PIN if applicable
CISA counts FIDO methods and security keys among phishing-resistant MFA solutions. For a typical user, though, it is not the first thing to buy.
Start with:
- unique passwords
- a password manager
- 2FA
- passkeys
- securing the phone and the recovery accounts
Those measures already deliver a considerable security gain.