Multi-Factor Authentication
Multi-factor authentication requires two or more independent proofs of identity at login. It typically combines something the user knows (password), something they possess (phone, hardware key), and something they are (biometrics).
Term
description · examples · notesMulti-factor authentication requires two or more independent proofs of identity at login. It typically combines something the user knows (password), something they possess (phone, hardware key), and something they are (biometrics).
Description
MFA drastically reduces the risk of unauthorized access even when a password is compromised, because the attacker must also possess the second factor. It is one of the most cost-effective security measures.
Different factors provide different levels of protection. Hardware keys and on-device authenticators are more phishing-resistant than SMS codes, but any form of MFA is significantly better than a password alone.
What people often say
- MFA makes an account completely impenetrable.
- SMS verification provides the same level of protection as a hardware key.
- MFA is only needed for administrator accounts.
Covers / does not cover
Covers
- Protecting accounts from login with a stolen password
- Additional verification layer for sensitive operations
- Hindering automated brute force and credential stuffing attacks
Does not cover
- Attacks that bypass MFA in real time by intercepting tokens or sessions
- Social engineering that tricks the user into approving a fraudulent request
- Threats that do not require authentication (e.g., exploitation of a public-facing service)
Mentioned in the news
- 11. AVG 2026. Passkey nije razbijen, ali kad je malver već u računaru, stvari se komplikuju →
- 11. MAR 2026. Microsoft uvodi phishing-otpornu prijavu na Windows kroz Entra passkeys →
- 13. JUL 2026. Trojanac u Visual Studio projektima ostavlja zamke za razvojne inženjere →
- 5. MAR 2026. Bitwarden uvodi podršku za passkey prijavu na Windows 11 →
Threats
reduces 21Threats it reduces. Select one to open its page.
- Infostealer→
- Spear Phishing→
- Account Takeover→
- Phishing→
- Business Email Compromise→
- Credential stuffing→
- Whaling→
- SMS phishing - Smishing→
- Token Theft→
- Brute-force attack→
- Session Hijacking→
- Password spraying→
- Pass-the-Hash→
- MFA Fatigue→
- SIM Swapping→
- Evil Twin→
- QR phishing - Quishing→
- Deepfake Attack→
- Pretexting→
- voice phishing - Vishing→
- Keylogger→
Techniques
neutralizes 7Techniques it neutralizes. Select one to open its page.