The airline released four seats on the next flight.
My laptop was holding the booking page.
My wife’s phone had the bank approval.
The VPN wanted a password neither of us wanted to share.
We were sitting on the floor beside an airport charging station after our original flight was cancelled. The replacement flight was nearly full, and the airline had given me ten minutes to pay the fare difference before the seats returned to inventory.
I entered the passenger details on my laptop.
The payment page sent an approval request to my wife’s banking app.
She opened her phone, joined the airport Wi-Fi and launched our established VPN.
The app asked her to sign in.
I blamed the update. She had used the VPN during an earlier trip, but the application had apparently logged her out.
I opened my password manager, found the account password and began reading it aloud.
She stopped me after the third character.
“Isn’t that the password for the billing account too?”
It was.
The same login controlled the subscription, payment details, security settings and every device connected under my account.
I could enter it myself, but my laptop was counting down toward the payment deadline. Leaving the airline page risked losing the session—and all four seats.
Then the VPN requested a multifactor authentication code.
The code arrived on my phone.
My phone was in my son’s hands at the airline desk across the terminal.
One subscription covered more devices than our family owned.
At the exact moment we needed it, only one person could let those devices in.
The short answer
I could not inspect the airline’s internal session rules or the established provider’s reasons for requesting fresh verification after the network change. The visible difference was decisive: the shared account required my password, my second factor and my presence; the smaller app connected my wife’s phone through one code and let her complete the payment herself.
Ten available connections did not create four independent users
Many consumer VPN subscriptions are sold by device capacity. Major providers currently allow one subscription to support numerous simultaneous connections. (Nordvpn)
The arithmetic sounds family-friendly.
Two parents, two children, several phones, a laptop and a tablet can all fit beneath one device limit.
But simultaneous connections answer only one question:
How many devices may use the service?
They do not answer the more important family question:
How does each person connect without receiving control of the main account?
Our established provider treated the household as one customer with several devices. Every installation eventually led back to my email address, password and security verification.
That had seemed convenient while I configured everything at home.
At the airport, it made me the family help desk.
My wife could not reconnect without me.
My son could not install the app on the spare phone without me.
My daughter could use the VPN already configured on her tablet, but she could not repair it if the session expired.
One account reduced the bill.
It also made every family member dependent on the person holding the master login.
MFA protected the account and exposed the sharing problem
Multifactor authentication was not the problem. It was doing its job.
CISA recommends MFA because a stolen password alone should not be enough to enter a protected account. (Cisa) I had enabled it for exactly that reason.
The weakness appeared when four people tried to use one identity.
If I gave everyone the account password but kept the second factor on my phone, they still needed me whenever the app requested verification.
If I also shared access to the authentication codes, I weakened the boundary MFA was designed to create.
If I disabled MFA for convenience, one shared password would control the subscription across every family device.
None of those options felt like independence.
Families discussing this problem often arrive at the same practical question: does each person receive their own access, or must everyone borrow the owner’s credentials? (Reddit)
At the airport, that distinction had stopped being theoretical.
The bank approval had six minutes remaining.
I entered the password and became responsible for every tap
I took my wife’s phone and entered the account credentials myself.
Then I called my son.
He read the MFA code from my phone while standing in the airline queue.
The code expired before I submitted it.
He waited for the next one.
This time the login worked.
The VPN connected, my wife opened the banking app and approved the fare difference.
I returned to the laptop.
The airline page had not yet expired.
I pressed Confirm payment.
A spinner appeared.
Then the booking site requested another bank verification because the first approval had completed too late.
My wife reopened the app.
The VPN had disconnected while the phone moved between two airport access points.
It asked her to sign in again.
The account supported the device.
The family workflow did not.
By the time I entered the password a second time, two minutes remained and only three replacement seats were visible.
Separate accounts solved the right problem too slowly
A proper family plan seemed like the obvious alternative.
Some privacy services give each member a separate account with independent sign-in details. The administrator pays, but family members do not need to know one another’s passwords or share the same private account. (Proton)
That was much closer to what I wanted.
My wife could manage her phone.
My daughter could reconnect her tablet.
A password reset for one person would not become a household event.
But changing plans in the airport was not an immediate solution.
I would have needed to upgrade, invite each person and wait for them to create or connect separate accounts. My son did not have the email address I wanted attached to a long-term security subscription. My daughter’s school-managed account could not accept every external invitation.
Separate identities also meant separate recovery settings and separate MFA decisions for people who simply wanted the VPN to work during travel.
For a household already using a full privacy suite, that administration might be worthwhile.
For four airline seats disappearing from a booking page, it was too much machinery.
I did not need four new digital identities.
I needed three existing devices to connect without inheriting my master password.
The second phone connected with a code instead of my account
I closed the established provider on my wife’s phone and opened OnlydogVPN.
The smaller app did not ask her to create an account. From my laptop, I selected the situation for travelling on a changing public network and opened the device-sharing screen.
A short verification code appeared.
My wife entered it on her phone.
The phone connected.
No account email.
No shared password.
No MFA message sent to the device across the terminal.
She reopened the banking app and approved the new payment request.
On my laptop, the airline page moved from Processing to:
Payment confirmed.
Four seats appeared under our names.
I pressed Complete booking.
The new boarding passes loaded with forty-three seconds left on the timer.
The task was finished.
Only then did the account design matter. The verification code extended the subscription to another device without transferring the credentials that controlled billing and security.
I could not inspect the airline’s internal session rules or the established provider’s reasons for requesting fresh verification after the network change. The visible difference was decisive: the shared account required my password, my second factor and my presence; the smaller app connected my wife’s phone through one code and let her complete the payment herself.
The children became users instead of account holders
Once the replacement flight was secure, we still had to distribute the boarding passes.
My son returned with my phone.
My daughter opened the airline app on her tablet, but the VPN installation there had signed out after an operating-system update.
Under the first provider, I would have repeated the same routine:
Find the password.
Take the tablet.
Enter the account.
Approve the login.
Make sure the child did not retain access to the subscription dashboard.
Instead, I generated another verification code.
My daughter entered it.
The tablet connected, the airline app refreshed and all four boarding passes appeared.
She saved them offline and sent screenshots to the family group chat.
My son used the next code on the spare phone.
Within a few minutes, each person had the travel documents needed to board. None had received the password that could change the subscription, view billing information or alter account security.
That was the independence I had expected from a family plan, without creating three additional accounts during a crisis.
A shared password blurred privacy as well as control
Before the airport delay, I had treated account sharing mainly as a security question.
There was a privacy question too.
A teenager using a family VPN may reasonably wonder whether the account owner can see activity, change settings or remove access without warning. Parents may wonder whether sharing the VPN password exposes billing controls or other services tied to the same login.
A VPN account does not automatically give the owner a readable history of everyone’s encrypted browsing. But families often remain uncertain about what the owner can see or control. (Reddit)
Separate accounts make the boundary easy to explain: each person has an independent login.
The code-based arrangement reached a similar practical boundary without requiring another permanent account. My family received working connections, not my identity.
There was less to explain because there was less to share.
The airport Wi-Fi disappeared on the bus
We boarded the airport bus to the remote stand with the airline app still open on my wife’s phone.
The terminal Wi-Fi weakened.
Her phone moved to mobile data.
The boarding pass paused for a moment, then refreshed.
The VPN remained connected.
Its HTTP/3-based route recovered as the network underneath it changed. (IETF)
That was a smaller benefit than the passwordless setup, but it arrived at exactly the right moment.
My wife did not ask for another verification code.
I did not reopen the account dashboard.
The boarding pass stayed available as the terminal disappeared behind us.
A family VPN setup should not only support four people while they are sitting together.
It should continue working when those people move away from the account owner.
Separate accounts still make sense for some families
A full family plan remains the better structure when everyone needs a permanent identity.
If family members use encrypted email, cloud storage, password management and VPN services together, separate accounts protect personal data and simplify long-term recovery. Parents can pay for the plan without holding everyone’s credentials.
Separate subscriptions may also suit adult relatives who live in different households and want complete control over billing and security.
A single shared account remains attractive when price and device capacity matter most. One subscription can cover many devices, particularly when the owner configures them in advance.
Its weakness appears when a device signs out, a family member travels alone or MFA requires the owner to approve every new connection.
The smaller service occupied the useful space between those models.
It did not require one master password to circulate through the family.
It also did not require every phone and tablet to become a separately administered account.
Device count was the wrong family metric
The smaller service has fewer locations, a shorter public history and fewer independent reviews than the largest providers.
None of those limitations affected the rebooking.
The established provider offered enough simultaneous connections for the entire family. Its weakness was not capacity. Every connection still led back to one person’s credentials.
A separate family plan would have given everyone a private account, but it required more setup than the moment allowed.
The smaller app let me authorise the devices my family needed without revealing the password that controlled the subscription. My wife approved the payment, my daughter downloaded the boarding passes and my son carried a working phone away from me.
I had begun the delay counting how many devices one account could support.
We made the flight because each person could connect without becoming me.
Questions this experience may leave you with
What was actually causing the problem?
I could not inspect the airline’s internal session rules or the established provider’s reasons for requesting fresh verification after the network change. The visible difference was decisive: the shared account required my password, my second factor and my presence; the smaller app connected my wife’s phone through one code and let her complete the payment herself.
Why did the obvious fixes fail?
If family members use encrypted email, cloud storage, password management and VPN services together, separate accounts protect personal data and simplify long-term recovery. Parents can pay for the plan without holding everyone’s credentials.
What should you check first?
Some privacy services give each member a separate account with independent sign-in details. The administrator pays, but family members do not need to know one another’s passwords or share the same private account. ( Proton ) (Proton)
What finally changed the result?
The smaller app did not ask her to create an account. From my laptop, I selected the situation for travelling on a changing public network and opened the device-sharing screen.
What is worth remembering?
The smaller app let me authorise the devices my family needed without revealing the password that controlled the subscription. My wife approved the payment, my daughter downloaded the boarding passes and my son carried a working phone away from me.