safeandsecure.ie/topics/cyber/passwords-and-security-keys

Passwords, password managers and security keys: a plain guide

Give your email a long password you use nowhere else, and turn on two-step login for your email and your bank. Never give anyone a code sent to your phone. A password manager or a security key can help, but they come second.

Last checked against the sources listed at the end of this page.

We sell nothing, and no company paid to be on this page. The few products named link to their makers’ own websites. None of those links earns us money.

Clay illustration of a laptop with a padlock on screen and a small security key beside it

The short answer

Free help first

The NCSC’s free booklet

The Government’s National Cyber Security Centre (NCSC) publishes “How to keep your online accounts secure” (opens in a new tab), a short booklet in plain English with a list of the words you need to know. Most of this page’s advice on passwords and two-step login comes from it.

A free tutor, if you would like help

Age Action’s Getting Started is a free programme to help older people get online, or use their phone or tablet with confidence (opens in a new tab). You are matched with a volunteer tutor for two hours a week, for five weeks, on the skills you want to learn: the things on this page, if you like. Phone 0818 911 109 to find out more.

Two-step login is already in your accounts

You do not need to buy anything for the most important step. The NCSC says many services, such as MyGov.ie, online banking and social media, offer two-step login (opens in a new tab). You usually turn it on in the account’s settings or security section.

Why do passwords matter so much?

The NCSC puts it simply: passwords are often the only barrier between you and your personal information (opens in a new tab). And it calls reusing one password on many sites a major problem.

Here is why. Companies are broken into every day, somewhere in the world, and the email addresses and passwords taken are then tried, automatically, on other services, such as email. The NCSC says a unique password is key to stopping this (opens in a new tab). A different password for each important account stops a hacker getting into your other accounts (opens in a new tab) if they find out one of them.

Why your email comes first

The UK’s National Cyber Security Centre says that a criminal who gets into your email could reset all your other account passwords (opens in a new tab), and so get into your other accounts too. That is why the NCSC in Ireland asks for two-step login especially on your primary email (opens in a new tab) and your financial accounts.

What makes a good password?

The NCSC’s rule of thumb: the longer your password or passphrase, the stronger it is (opens in a new tab). Its advice, in its own booklet:

Keep it to yourself

A password should be a secret that only you know (opens in a new tab). The NCSC adds that a real customer service or helpdesk worker will never ask for your password, passphrase or PIN: only a scammer will.

What is two-step login, and where should I turn it on?

Two-step login means that after your password, you also need a code sent to your phone, app or email (opens in a new tab), or your fingerprint. The NCSC compares it to having two locks on your door instead of one. You may see it called two-factor authentication (2FA), multi-factor authentication (MFA) or two-step verification. They all mean much the same thing.

Turn it on wherever you can. The NCSC says especially for your primary email, your financial accounts and your health records (opens in a new tab), and on all email and social media accounts (opens in a new tab). The Gardaí’s own advice on hacked accounts says the same: use two-factor authentication to secure your accounts (opens in a new tab).

To find it, look in the account’s settings or security section. The NCSC says it may be listed as “Two Factor Authentication” (opens in a new tab).

Which kind of code?

A code by text message is better than nothing, but the NCSC ranks it the weakest kind (opens in a new tab). An authenticator app (an app on your phone that makes temporary codes) is stronger, and a passkey or security key is the strongest. Any of them is far better than a password on its own (opens in a new tab).

Never share the code

The code is the second lock, so whoever has it can get in. The NCSC says never share this code with anyone (opens in a new tab). One trick the NCSC has warned about is a WhatsApp message from a friend’s account, urgently asking you to pass on a code sent to your phone. Its advice: think of the code as a password, never to be shared (opens in a new tab).

Our ScamWatch pages show two more ways it is tried: the Vodafone “loyalty discount” call and the credit union “new payee” text. Both are after a one-time code.

And only approve a sign-in you have just started yourself. The NCSC says you should only get these requests if you have tried to log in (opens in a new tab), and warns of scammers who send prompt after prompt (opens in a new tab) until someone approves one by mistake.

What is a password manager, and do I need one?

A password manager is a program that creates strong passwords and stores them in one place (opens in a new tab). The NCSC calls it an online safe. It can fill in your username and password for you, and you only need to remember one strong password: the one that opens it.

A separate app is worth a look if you use a mix of devices, say an iPhone and a Windows computer: the UK’s NCSC says its main benefit is that it can keep your passwords in step across different browsers and devices (opens in a new tab). These two have free plans.

These are examples, not the only good choices. We name them from what their makers publish. We have not tested them ourselves, and no link here earns us anything.

Research to know about

In February 2026, researchers at ETH Zurich published attacks on three password managers, Bitwarden, LastPass and Dashlane (opens in a new tab). The attacks work if the company’s own server has been broken into; the researchers tested them on servers of their own, built to behave like hacked ones. Their advice: choose a password manager that is open about security problems, is checked by outside auditors and, at the very least, has end-to-end encryption switched on as standard.

What are passkeys and security keys?

The NCSC says passkeys are beginning to replace passwords (opens in a new tab). A passkey lets you sign in without typing a username or password: you approve it the same way you unlock your phone or computer, with your fingerprint, face, PIN or pattern. The FIDO Alliance, which writes the standard, says a passkey can be stored on your phone or computer, or in a hardware security key (opens in a new tab), and that your fingerprint or face stays on the device and is never sent (opens in a new tab) to the website. There is no password to steal, and passkeys are, in its words, “phishing resistant” (opens in a new tab).

When a new account suggests a passkey or two-step login, the NCSC’s advice is short: “You should use them.” (opens in a new tab)

Security keys: for people who want more

A security key is a small key that holds your passkeys. You plug it into a computer or tap it against a phone. The NCSC calls sign-in of this kind (the FIDO standard) “currently the gold standard” (opens in a new tab). The FIDO Alliance adds that security keys are not only for people at special risk: for some people, a key with a PIN and a single touch can be simpler than a phone (opens in a new tab).

Before you buy one, check your phone and the accounts you use. A key that taps needs a phone with NFC (opens in a new tab) (the tap feature), and the website or app must accept security keys: Yubico keeps a list of the services that work with its keys (opens in a new tab). Yubico also recommends having two keys, one kept as a backup (opens in a new tab), so that losing one does not lock you out.

These are examples, not the only good choices. We name them from what their makers publish. We have not tested them ourselves, and no link here earns us anything.

Yubico

YubiKey 5 NFC

Good for: a computer with the older, rectangular USB port (USB-A), and a phone you can tap it against (NFC).

  • Plug it in, or tap it on a phone or tablet that has NFC.
  • Holds passkeys (FIDO2) on the key itself, and needs no battery.

Check it works: check your phone has NFC, and that the accounts you use accept a security key: Yubico keeps a list.

From Yubico’s Irish store page (opens in a new tab), checked 7 October 2026.

See it on Yubico’s site (opens in a new tab)

Yubico

YubiKey 5C NFC

Good for: newer laptops, tablets and phones with the small, oval USB-C port, and phones you can tap it against (NFC).

  • Plug it in, or tap it on a phone or tablet that has NFC.
  • Holds passkeys (FIDO2) on the key itself, and needs no battery.

Check it works: check which port your computer and phone have, and that the accounts you use accept a security key.

From Yubico’s Irish store page (opens in a new tab), checked 7 October 2026.

See it on Yubico’s site (opens in a new tab)

Can I write my passwords down?

The NCSC’s booklet for everyone says a password should be a secret that only you know (opens in a new tab). In its advice on keeping work devices safe at home, it says “Do not write down or share your passwords” (opens in a new tab).

If there are too many to remember, that is the job a password manager does: it remembers them for you, behind one main password. And never write a password or PIN on any of our printable sheets.

What if I think an account has been hacked?

Our page Your email or social media account has been hacked goes through it step by step: how to tell whether your account was taken over or copied, how to get back in, and the evidence to keep.

Two free sheets on staying safe online and on the phone, to print, keep and give to family or neighbours.

All printable safety sheets

Your accounts, step by step

Start with the account that matters most: your email. Then work down the list.

  1. 1

    Give your email a new, long password

    Three or four random words, with a number or symbol added, and 12 characters or more. One you use for nothing else.
  2. 2

    Turn on two-step login for your email

    Look in its settings or security section for “two-step”, “two-factor” or “2FA”.
  3. 3

    Then your bank, MyGov.ie and anything to do with money or health

    Two-step login on each one, and each with its own password.
  4. 4

    Check the backup email address on your email account

    Make sure it is one you still use. The Gardaí point to the backup email account (opens in a new tab) as a way back in if you are ever locked out.
  5. 5

    Too many passwords? Use a password manager

    The one in your phone or browser, or an app. Protect it with one strong main password you remember, and two-step login.
  6. 6

    When a site offers you a passkey, you can say yes

    You then sign in with your fingerprint, face or phone PIN instead of a password.
  7. 7

    Never give anyone a code, and only approve a sign-in you started

    Not a caller, not a text, not a friend on WhatsApp. Whoever they say they are.

Your accounts: a checklist

Tick each line as you do it. Never write a password, passphrase or PIN on this sheet.

My email

  1. A long password I use for nothing else

    Three or more random words, 12 characters or more.

  2. Two-step login turned on

  3. Its backup email address is one I still use

My bank and other important accounts

  1. Two-step login turned on for online banking

  2. Each important account has its own password

  3. A passkey set up where a site offers one

    Only if you would like to.

Every day

  1. I never give anyone a code sent to my phone

  2. I never tell anyone my password or PIN

    A real helpdesk never asks for them.

  3. I only approve a sign-in I started myself

If I use a password manager or a security key

  1. Its main password is strong, and I remember it

  2. Two-step login is on for the password manager itself

  3. A spare security key is set up on my accounts, kept somewhere safe

From safeandsecure.ie/topics/cyber/passwords-and-security-keys. Last checked 7 October 2026. Sources: National Cyber Security Centre (ncsc.gov.ie): online account security booklet, Multi Factor Authentication guide, Phishing quick guide, WhatsApp code advisory; An Garda Síochána (garda.ie); FIDO Alliance (fidoalliance.org); Yubico (yubico.com).

The checklist prints on one page, in black on white, with a box to tick beside each line. The whole guide prints without the menus, and with the address of every source.

One thing to do this week

This week, turn on two-step login on your email account.

Open your email’s settings or security section and look for “two-step”, “two-factor” or “2FA”. The NCSC says to use it wherever you can, especially for your primary email (opens in a new tab). If a code ever arrives that you did not ask for, do nothing with it, and never read it out to anyone.

Sources

Every fact on this page comes from one of these, and each was read on 7 October 2026.