

0 / 2 embers
0 / 3000 xp
click for more info
Complete a lesson to start your streak
click for more info
Still calibrating
click for more info
Not enough gems
Cost: 6 gems
1: Multi-Factor Authentication
incomplete
2: TOTP
incomplete
3: Hardware Tokens
incomplete
4: Passkeys
incomplete
5: Choosing an MFA Method
incomplete
6: Account Recovery
incomplete
Back
ctrl+,
Next
ctrl+.
This lesson's interactive features are locked, please to keep using them
A stolen password shouldn't be enough to take over an account. If a password is your only barrier, an attacker who nabs it is in.
Multi-factor authentication (MFA) requires proof from two or more distinct factor types:
A password plus a PIN... is still weak. Both are "something you know." We need to mix factor types. A physical security key is a good second factor for a password because it's "something you have." A fingerprint or face can activate an authenticator, but a biometric characteristic isn't an authenticator by itself.
Obviously, we don't want passwords to get stolen... but it happens. MFA makes stolen passwords less useful, because an attacker still needs control of a separate authenticator. Common second factors include: