[ MF-05 · Multi-Factor Authentication ]
Multi-factor authentication: the setting that turns a stolen password into a dead end
Multi-factor authentication asks for something besides your password: a code from an app, a tap on your phone, a physical key or a passkey stored on your device. If someone has your password but not the second factor, the login fails. It’s the single setting we’d ask everyone to turn on today.
Not all methods are equal. Text-message codes can be intercepted through SIM swaps. Push prompts can be abused by attackers who spam them until someone taps “approve” out of annoyance. Authenticator apps are stronger, and passkeys or hardware keys resist phishing because they only work on the real site. But any second factor is far better than none.
This section walks through setup on the accounts that matter most, what to do with backup codes, how to avoid locking yourself out when you change phones, and how small teams can require MFA without a revolt.
Coming up: a beginner’s guide to multi-factor authentication and the mistakes that lead to lockouts.
Briefings in Multi-Factor Authentication
No briefings filed in this section yet. The wire below is tracking the topic until our first one lands.
Reporting from SecurityWeek
- Kontext Security Emerges With $4 Million for AI Agent Runtime ControlsSecurityWeek
- OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public DataSecurityWeek
- AI-Powered Campaign Targets Hundreds of Online RetailersSecurityWeek
- Island Raises $400 Million at $6.4 Billion ValuationSecurityWeek
- OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS IntegratorsSecurityWeek
- Begin at the End: How to Enable Agentic RemediationSecurityWeek