Multi-factor authentication requires more than one proof of identity before granting access. A password alone is one factor. A password plus a code from your phone is two. The point is simple: if an attacker steals your password, they still cannot get in. MFA blocks the overwhelming majority of credential-based attacks, which is why it sits near the top of every security checklist.
The factors come in three broad categories. Something you know: a password, a PIN, a security question. Something you have: a phone, a hardware token, a smart card. Something you are: a fingerprint, a face, a voice. Strong MFA pulls from at least two different categories. Two passwords are not MFA. A password plus a security question is weak, because both are knowledge factors that can be guessed or phished.
Common MFA methods
- SMS codes — convenient, but vulnerable to SIM swapping
- Authenticator apps — time-based codes, stronger than SMS
- Hardware keys — physical devices, resistant to phishing
- Push notifications — approve or deny on a phone
- Biometrics — fingerprint or face as a second factor
Not all MFA is equal. Push fatigue attacks, where an attacker spams approval requests until the victim taps accept, have defeated app-based methods. Number matching and hardware keys close that gap. Choose the strongest method your systems support, and turn it on everywhere it is offered.
Comments
No comments yet. Be the first to share a thought.
Leave a comment