What this is about
Your phone asks you to confirm a sign-in, a caller wants a code, an app offers a passkey. Five situations — the question is always: did I start this myself?
What you practise
Understand two-step verification and passkeys, decline requests you didn't make and never pass on codes.
The interactive exercise needs JavaScript. Without it, you can read through all messages with their explanations here.
Approve sign-in?
New sign-in to online banking
Device: computer · Location: unknown · just now
You're having dinner and aren't signing in anywhere.
What do you do?
- ✓ Decline — and then change your password, in the app you open yourself. – Exactly. Someone seems to know your password but can't get past the second key. Change the password so it stays that way.
- ✗ Approve, so the message goes away. – That would let strangers into your online banking. Only approve sign-ins you've just started yourself.
- ✗ Swipe it away and carry on eating. – Nearly: swiping keeps the door shut. But someone knows your password — change it, or the next request will soon follow.
A trap: approving a sign-in you didn't start lets strangers in. The second key worked here — now change your password too.
Approve sign-in?
New sign-in at flickerhaven.example
Device: computer · just now
You've just signed in to Flickerhaven on your computer yourself — from your bookmark.
What do you do?
- ✓ Approve — you've just started this sign-in yourself. – Exactly. That's what the approval is for: proving it really is you.
- ✗ Decline — requests like this are always scams. – Not always: you triggered this one yourself. What matters is whether you're signing in right now.
Genuine. You started the sign-in yourself — that's exactly what the approval is for. The question is always: did I just start this myself?
Approve sign-in? (6th request)
New sign-in to your account
Device: unknown · just now
For ten minutes this question has kept coming back, in the middle of the night.
What do you do?
- ✓ Decline every time, change your password and let Tidewren know on a number you trust. – Exactly. The flood is meant to wear you down. Declining costs nothing — and a new password stops it.
- ✗ Approve once, just to get some peace. – That's exactly what attackers are waiting for: someone tapping “Approve” out of annoyance or by accident.
A trap: wearing you down. Attackers who know your password send request after request until someone approves out of annoyance. Decline, change the password, tell the provider.
Flickerhaven Support · 0800 ••• ••• 61
Caller: Hello, Flickerhaven support. Someone is trying to take over your account right now. We've sent you a confirmation code to protect it — please read it out to me and we'll lock the intruder out.
On your phone: “Your Flickerhaven code: 48•••1. Never share this code.”
What do you do?
- ✓ Hang up. You give the code to nobody — it's the second key. – Exactly. The code doesn't lock anyone out — it lets the caller in. The intruder is the caller.
- ✗ Read out the code — it's about protecting your account. – Then he'd have your account. If the message says “never share”, that includes callers claiming to be support.
A trap: anyone asking for your code on the phone wants your account. A one-time passcode is like a key — you don't hand it over, not even to “support”.
In your Kestrelmoor Bank app
“Sign in with a passkey from now on — with your fingerprint, face or phone PIN.”
You opened the app yourself.
What do you think?
- ✓ Set it up — a passkey only works on the bank's genuine site. – Good. A passkey can't be typed into a fake site — it's tied to the real address. The NCSC now recommends passkeys wherever they're available.
- ✗ Decline — otherwise the app sends my fingerprint to the bank. – Your fingerprint stays on your phone. The bank only learns that the check succeeded — it never gets the fingerprint itself.
Well done. A passkey replaces the password and only works on the genuine site — a fake one gets nothing. Your fingerprint never leaves your device.
The second key in brief
Password plus proof
With two-step verification, a stolen password alone isn't enough: signing in also needs your phone — a code or a confirmation in an app.
Passkeys go further
A passkey replaces the password. You confirm with your fingerprint, face or phone PIN, and it only works on the genuine site. Since April 2026 the NCSC recommends passkeys wherever they're available.
Did I just start this?
Only approve a sign-in you started yourself, a moment ago. Everything else: decline, then change your password.
Codes stay with you
A code from a text or an app is a key. Nobody genuine asks you to read it out — not the bank, not customer service.
To do at home
Ticks are just for now — nothing is saved.
Sources (checked 1 October 2026)
NCSC, Turn on 2-step verification, Leave passwords in the past — passkeys are the future and Passkeys are more secure than traditional ways to log in (both 23 April 2026) · Stop! Think Fraud, Passkeys and 2-step verification · US agency CISA, Implementing Number Matching in MFA Applications (October 2022, on being worn down by requests) · FIDO Alliance, Passkeys (your fingerprint stays on the device). · Call voices synthesised with Piper from the CSTR VCTK Corpus (Yamagishi, Veaux and MacDonald, University of Edinburgh, 2019, CC BY 4.0; changed: speech synthesis, telephone filter).
All companies, people, addresses and numbers in the exercises are invented. Any resemblance to real companies or people would be purely coincidental and unintended.