Knowledgebase

When Two-Factor Is Not Enough Print

  • passwordsmanagement, passwords, twofactor, password, security, hacked, troubleshooting, guide
  • 0

Its limits.

WHAT IT DOES NOT STOP

A compromised device, where the attacker has the codes too An active session already authenticated Approval fatigue, where you approve a prompt without thinking Someone tricking you into entering a code on a fake page

THE FAKE PAGE ATTACK

A convincing page captures both your password and the code you enter.

The attacker uses both immediately.

WHAT PREVENTS THAT

Not clicking links in messages about accounts.

Going to the site directly.

THE APPROVAL FATIGUE PROBLEM

Repeated prompts until someone approves one to stop them.

If you receive a prompt you did not trigger, deny it and change your password.

That means someone has your password.

WHAT IS STRONGEST

A physical security key, which cannot be used on a fake site.

WHAT ELSE TO DO

Keep devices updated Do not approve anything you did not initiate Log out of sessions you are not using

WHAT TO REMEMBER

Two-factor is very strong and not absolute.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot