Ways of proving identity.
WHAT THE FACTOR CATEGORIES ARE
Something known Something held Something inherent
WHAT MULTI-FACTOR MEANS
Factors from different categories.
WHY TWO PASSWORDS ARE NOT TWO FACTORS
They are the same category, and fall to the same attacks.
WHAT PASSWORDS SUFFER FROM
Reuse Phishing Credential stuffing from other breaches Difficulty remembering unique ones
WHAT CODES BY MESSAGE SUFFER FROM
Interception and number redirection Delivery unreliability and cost Phishing, since codes can be relayed
WHAT AUTHENTICATOR APPLICATIONS IMPROVE
Removing the delivery channel, and its interception.
WHAT THEY DO NOT PREVENT
Relaying a code to a fraudulent site.
WHAT HARDWARE SECURITY KEYS PROVIDE
Cryptographic proof bound to the site's identity.
WHY THAT MATTERS
The proof is useless to a fraudulent site, which defeats phishing.
WHAT PASSKEYS PROVIDE
The same protection, with the key held by the device and unlocked biometrically.
WHY THEY MATTER
Phishing resistance without carrying a separate device.
WHAT TO RECOMMEND
Passkeys where supported, with a fallback.