Module 3: Beyond Passwords
Module 3: Beyond Passwords
Module 2 made your passwords unguessable and unique. Now for the uncomfortable part: none of that survives a good phish. A password’s fatal flaw isn’t weakness. It’s that it can be told to the wrong door. A convincing fake login page doesn’t crack anything; it just asks, politely, and people type. The strongest password in the world protects nothing once you’ve entered it at paypa1-secure.com.
So this module adds what passwords can’t provide: proof that it’s really you, given in ways that can’t be typed into the wrong place. First the second lock, two-factor authentication. Then the thing that retires the password entirely: the passkey.
This module also holds the course’s showpiece. In Lesson 3.3 you won’t just read about passkeys — you’ll create a real one, live on the page, watch your device’s biometric prompt appear, sign in with it, and throw it away. Five minutes, and the fog around the word “passkey” lifts for good.
Four lessons:
- The 2FA Ladder — from SMS codes to authenticator apps to passkeys: what each defends against, and which rung to stand on
- What a Passkey Actually Is — the key pair, the padlock metaphor, and why there’s nothing to phish
- Make One Right Now — the live demo, then a passkey on one real account
- Recovery Without Lockout — the “what if I lose my phone?” fear, answered properly
What you’ll walk away with
- App-based 2FA on your master-key email — set up during 3.1, not after it
- An understanding of passkeys solid enough to explain at dinner
- A passkey on at least one real high-value account
- Recovery codes stored where they belong, so extra security never turns into a lockout
Time
About 45 minutes including the hands-on pieces. When you finish, every account on your Lesson 1.4 list is defended in depth. Then Module 4 turns to your devices and network, and Module 5 builds your early-warning system.