BRF-05 / Multi-Factor Authentication

Multi-factor authentication: a second lock for the accounts you can't afford to lose

Multi-factor authentication, or MFA, means a stolen password isn't enough. After the password, the site asks for a second proof: a code from an app, a tap on your phone, a physical security key, or a passkey.

Not all second factors are equal. Text-message codes are far better than nothing, but they can be intercepted or talked out of you. Authenticator apps are stronger. Security keys and passkeys are the hardest to phish, because they check which website is asking before they answer.

The weak spot is usually the person, not the technology. Attackers send a flood of approval prompts hoping you'll tap Approve to make them stop, or they call pretending to be support and ask you to read out the code. This section covers setting up MFA on email, banking and social accounts, saving backup codes, and the one rule that beats both tricks: never approve a sign-in you didn't start.

Red flags

  • An approval prompt appears when you aren't signing in.
  • Someone asks you to read them a verification code.
  • You get several prompts in a row, often late at night.
  • A text claims your MFA is expiring and needs a reset link.

5-minute security check

  • Turn on MFA for your main email account.
  • Move from text codes to an authenticator app where you can.
  • Save backup codes somewhere offline.
  • Tell your team that real support never asks for a code.

Multi-Factor Authentication briefings

No multi-factor authentication briefings are filed yet. The first one is in the works; until then, the headlines below track what’s happening.

Current attack reporting from The Hacker News

Keep reading

Follow on Google News