Hey Enrico,
thanks – good point, and yeah: more factors are always better.
You can set up login with Passkey directly in your account under Passkeys – and just now we added the option to enforce it: once activated, password-only login is blocked for your account, so you can only log in with a Passkey. Passkeys are tied to the real domain and are therefore phishing-proof (a classic authenticator code can be phished, a Passkey can’t) – that’s why we deliberately rely on them instead of code apps.
When you activate it, you get recovery codes once – please keep them safe (e.g. in your password manager) so you can get back in if you lose your Passkey. The safest bet is to set up two Passkeys right away (like phone + laptop).
And on top of that, with remote control of your sites, there’s another layer: the signing key lives only in your browser (with its own recovery code). So making changes to your sites also requires this local key – all in all, a multi-layered, basically 3-factor protection. 🙂
Cheers
Pascal