MFA
In short: MFA (multi-factor authentication) requires several independent proofs for login.
In more detail: Besides the password, a second factor is checked. The factors come from three categories: knowledge (password, PIN), possession (phone, hardware key) and inherence (fingerprint, face).
In Depth
Methods
- One-time codes via app (TOTP).
- Push approval in an app.
- FIDO2/WebAuthn and passkeys: cryptographic proof that cannot be phished.
- SMS codes: better than nothing, but vulnerable (SIM swapping).
Benefit
Even a stolen password is not enough for the attackers. See 2FA, authentication.
Limits
Against stolen session cookies (infostealers) and “MFA fatigue” (constant pushes), MFA helps only to a limited extent.
See also: 2FA, Authentication, SSO, Phishing