Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 316, Issue 5IT NewsMFA

Is Your MFA Broken?

Security Boulevard, Tuesday, July 30th, 2024

Multifactor authentication (MFA) has formally been around for more than two decades, gaining the most traction in the mid-2000s. At the most basic level, MFA is 'something you know (a password),' 'something you are (a unique biometric or behavioral characteristic),' and 'something you have' (a token or security key) to verify an identity.

There are many forms of MFA available today, including SMS, email, and mobile one-time passwords; mobile app push notifications with or without number matching; mobile app with FIDO2; and mobile app with certificate-based authentication (CBA).

Another common form of authentication that has also been around for a long time - 25 years, in fact - is two-factor authentication (2FA), which requires just two authentication types. However, in more recent years, and with the substantial rise in cybercriminal activity such as phishing attacks that are now able to bypass these identity security technologies, traditional 2FA along with MFA just aren't cutting it anymore.

In this post, we'll review the history of authentication methods, the current challenges with MFA, and why organizations should implement phishing-resistant MFA to minimize their risk.

more →  ·  More from MFA →