Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

When you log in, your browser first establishes an encrypted HTTPS connection to the website. The site then checks your sign-in method—such as a password or passkey—and, if it succeeds, usually creates a session so you can keep using the site without signing in again on every page. These are separate jobs: HTTPS protects the connection and helps verify the site; authentication checks access to your account.

1. Your browser connects to the website over HTTPS

HTTPS uses Transport Layer Security (TLS) to protect data travelling between your browser and the site. During the TLS handshake, they negotiate connection settings and establish keys for protected communication. Your browser also checks the site’s certificate and its relationship to the domain you requested. This helps confirm which site you reached and protects traffic in transit; it does not prove that you own an account on that site. MDN’s TLS guide recommends serving pages and subresources over HTTPS and implementing server authentication.

The browser’s security indicator is about the connection, not a guarantee that the account or website is safe in every respect. TLS does not protect you from a deceptive site you chose to visit, a compromised device, or flaws in the site’s own account security.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. The site checks how you prove account access

The precise steps depend on the site and the sign-in method. A password, a one-time code, an identity provider, and a passkey do not work identically, and a site may combine methods.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Password

With a password login, the browser submits the username and password to the site over the protected connection. The server finds the account record and checks the submitted password against the stored credential representation; a well-designed system does not store passwords as readable plain text. The server should also avoid revealing whether a username exists. MDN’s password guidance says that if no record is found or the comparison fails, the server should return the same error message in either case.

One-time code or identity provider

A one-time password (OTP) adds a code-based step to the sign-in process. Depending on the setup, you may receive or generate that code separately from your password. With federated sign-in, another identity provider handles part of the authentication process and tells the site whether sign-in succeeded. The details vary by provider and site; neither method is a universal feature of every account.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Passkey and WebAuthn

In a passkey flow, the site sends a challenge for an authenticator associated with the account. The authenticator uses a device-held private key to sign the challenge, and the site checks the signed response using the corresponding public-key information. The private key is not sent to the site. A device may ask you to unlock the authenticator, for example with a PIN or biometric check; that does not mean your biometric data is sent to the website. Where both the site and device support it, a physical security key can also act as a WebAuthn authenticator. MDN describes the challenge and authenticator model in its WebAuthn API documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. What the login methods ask of you

Each method relies on different proof and has different practical trade-offs. A method’s protections also depend on the site’s implementation and the recovery options it provides.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Method What proves access What you need Practical security consideration
Password A memorized secret submitted to the site The password and the account identifier A password reused elsewhere can be exposed if another service is breached. HTTPS protects its transmission to the site, but does not prevent reuse-related risk.
Password plus one-time code A password and a separate code step The password and access to the method that provides or generates the code The extra step can make a stolen password alone insufficient, but the exact protection depends on the code method and site.
Federated sign-in A successful authentication assertion from an identity provider Access to the provider account and a site that supports the integration Sign-in relies on both the provider’s account security and the site’s integration; recovery arrangements vary.
Passkey A signed challenge produced with a private key held by an authenticator An available authenticator and a site that supports passkeys The private key is not sent to the site. A passkey is designed to resist phishing, but device access and account recovery still matter.

No method is supported on every site. Check the site’s sign-in and recovery settings before relying on a particular option.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

4. After sign-in, a session keeps you logged in

Once authentication succeeds, the site commonly creates a session. It may send the browser a cookie containing a secret session identifier. The browser stores that cookie and returns it with later requests when the cookie’s configured rules allow; the server uses the identifier to associate those requests with the signed-in session. This is why you can move between pages without entering your password each time. MDN explains the relationship between cookies and sessions in its HTTP cookie guide and session management guidance.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

A session identifier is a bearer secret: someone who obtains it may be able to act as that session. It is not the user’s real-world identity, and the cookie itself does not re-check the original password or passkey on every request. The site’s session handling, expiration rules, and account safeguards therefore matter after the initial login too.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. How sites limit session-cookie exposure

Cookie attributes reduce specific risks, but none makes an account immune to attack. For a session cookie, MDN recommends safeguards such as Secure, which limits sending to HTTPS connections, and HttpOnly, which prevents page JavaScript from reading the cookie. Narrow host/domain and path scope can limit where the browser sends it. SameSite can restrict some cross-site sending and reduce certain cross-site request forgery (CSRF) risks, but it is not a complete CSRF defense. The __Host- prefix can enforce additional host-only cookie requirements in supporting browsers. See MDN’s secure cookie configuration guidance.

  • Secure: the browser sends the cookie only over HTTPS.
  • HttpOnly: page JavaScript cannot read the cookie.
  • Narrow scope: the browser sends the cookie only for the configured host or path.
  • SameSite: the browser limits some cross-site cookie sending; sites may still need other CSRF protections.

Cookies are sent according to their configured rules, not simply because a page has a login form. A site’s implementation and your device’s security still affect how well the whole sign-in process is protected.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.