Guide
What Is Multi-Factor Authentication?
Guide
Multi-factor authentication requires a user to verify their identity in more than one way before gaining access. A password alone can be guessed, stolen or phished. Adding a second or third factor makes that harder.
But not all additional factors provide the same protection. A six-digit SMS code and a hardware-bound biometric both count as a second factor. They are not equally secure. Understanding why requires understanding what each factor actually does and what an attacker needs to defeat it.
Authentication factors fall into three categories.
Knowledge factors are things you know: passwords, PINs and security questions. They are the weakest category because knowledge can be extracted. Phishing captures it. Data breaches expose it. Security questions can be answered using public information.
Possession factors are things you have: a phone that receives an SMS code, a hardware token, a smart card. Possession is stronger than knowledge because an attacker must obtain the physical object or intercept the communication channel. SMS codes sit at the weaker end of this category because the code can be intercepted in transit or relayed in real time. Hardware tokens that generate locally and never transmit a code sit at the stronger end.
Inherence factors are things you are: fingerprints, facial geometry, iris patterns. Biometric factors cannot be guessed or phished. Their security depends heavily on where the biometric data is stored and verified. On-device verification, where the biometric never leaves the hardware, is significantly stronger than server-side verification.
The distinction between factor categories matters less than what an attacker needs to defeat a specific implementation.
SMS codes, authenticator app OTPs and push notifications all qualify as MFA. They all require a second factor beyond a password. But each produces a value that can be intercepted, relayed or approved under social pressure. The factor exists. It can be bypassed.
A factor that is bound to a specific device and requires a live biometric match cannot be relayed because there is no transferable value. The authentication happens on the hardware. Nothing leaves it that an attacker can use elsewhere.
The question to ask of any MFA implementation is not whether it adds a second factor. It is whether the second factor produces anything an attacker can capture and replay.
The most effective attack against legacy MFA today is the relay attack.
An attacker sets up a phishing site that looks identical to the real login portal. When the victim enters their credentials, the attacker’s proxy forwards them to the real site immediately. The real site triggers an MFA challenge. The proxy mirrors that challenge back to the victim. The victim enters their code or approves the push notification. The attacker forwards the response. The real site authenticates the session.
The exchange takes seconds. The code is valid. The login is legitimate. The victim does not know the breach has happened.
This works against SMS codes, OTPs and push notifications because all three produce something that can be captured and forwarded within the factor’s validity window. The attacker is not breaking the authentication. They are sitting in the middle of it.
Phishing-resistant MFA eliminates the relay by removing the transferable factor entirely.
The FIDO2 standard achieves this through origin binding. When a user registers with a FIDO2-compliant service, the authenticator generates a key pair specific to that service’s domain. During login, the server issues a challenge bound to that exact domain. The authenticator signs the challenge with the private key. A phishing site operating on a different domain cannot produce a valid challenge. A relay cannot forward one that resolves correctly.
This is what distinguishes phishing-resistant MFA from legacy MFA. Not the number of factors. Not the presence of biometrics. The binding of the credential to a specific origin so that an attacker positioned between the user and the real site has nothing to work with.
The most advanced forms of MFA today are hardware security tokens that are phishing-resistant, reducing the burden on users to discern the legitimacy of the relying party. Protocols like FIDO enable secure and simple authentication processes, eliminating the need for remote storage of secret keys. All secret credentials are generated on the user’s hardware security token, ensuring their protection and eliminating the need for users to determine the website’s legitimacy. However, deploying such devices at scale can be challenging. Therefore, next-generation MFA should combine the scalability and user-friendliness of authentication applications with the security provided by hardware security tokens.
With the TokenCore™ products, enterprise users can achieve the best of both worlds. This hardware product offers the same security assurances as the FIDO protocol, including phishing resistance and decentralized credential management, while minimizing the user burden. Users simply need to touch their fingerprint to the fingerprint sensor on the device, verifying multiple factors of authentication in a single step. Furthermore, these devices are designed to seamlessly integrate with all the devices and platforms users encounter within an enterprise environment.
They integrate with all the major identity and access management (IAM) systems, SSO providers like Okta, Microsoft, and Google, and enable direct passwordless authentication for websites and services that support passwordless FIDO login.
Enterprise customers can be confident that the individuals using the Token smart ring are who they claim to be, as user verification occurs on the device, and biometrics remain securely stored within the product. Additionally, the private keys used for FIDO authentication are generated on the device and never leave the secure element. With Token’s next-generation solution, enterprise customers gain access to a software platform that facilitates inventory management and deployment of these hardware products, resembling the familiar software-as-a-service interfaces that enterprise IT and CISO admins have come to expect.
With TokenCore™, enterprise customers can enjoy exceptionally high levels of assurance and security akin to hardware security tokens, while simultaneously benefiting from the scalability and user-friendliness of software-based solutions.
Furthermore, the TokenCore™ Wearable offers field upgradability, allowing for future enhancements to the user experience, supported features, or security improvements without the need for enterprises to replace their entire fleet of hardware security keys, as they would with traditional solutions.
Cyberattacks are becoming much more sophisticated, meaning that organizations need stronger means of security. Old methods of verifying your identity, like receiving a code via text or using a token, aren't enough anymore. Scammers can bypass these with tricks like SIM card swapping or phishing emails that steal your information.
TokenCore™ Wearable overcomes today’s security challenges by storing biometric data directly on the ring, so private data isn’t available elsewhere. This translates to better safety and smoother logins—just tap your ring with your scanned finger and you're in. The Token Ring's smart use of biometrics and on-device storage is changing the game for extra-secure logins.
As hackers get smarter, defenses need to as well. Security-conscious organizations are adopting Next-Generation MFA – keeping their sensitive data secure today and into the future.
Request a demo today and see how Token’s Next-Generation MFA can secure your organization from phishing and ransomware attacks with ease and simplicity.
Multifactor Authentication (MFA) is a security method which requires multiple forms of verification (like a password, a security token, and a fingerprint) to ensure a higher level of security compared to single-factor authentication
Using multifactor authentication (MFA) adds an extra layer of security beyond just a password. It’s a lot harder for attackers to get in because MFA requires more than one way to verify your identity—like something you know (a password) and something you have (a security key or your phone). This approach makes it much tougher for hackers to bypass your login, protecting your accounts and data from being compromised.
MFA enhances security by requiring multiple verification factors, making it significantly harder for unauthorized users to gain access even if one factor, like a password, is compromised.
The common types of authentication factors used in MFA are knowledge factors (something the user knows, like a password), possession factors (something the user has, like a smartphone), and inherence factors (something the user is, like a fingerprint).
In online banking, MFA might involve entering a password (knowledge factor) and then receiving a one-time password (OTP) on a smartphone (possession factor) to gain secure access.
Adaptive multi-factor authentication, or risk-based authentication, adjusts the security requirements based on the risk level of the login attempt, such as asking for additional verification if the login is from an unusual location.
Keep reading
Identity assurance covers more ground than a single guide. Dig deeper into the frameworks, threats, and decisions that define modern access control.
Learn about the most common types of cybersecurity threats, including malware, phishing, ransomware, insider threats, and denial-of-service attacks, plus strategies to reduce cyber risk.
Learn what CISA recommends for phishing-resistant MFA, why FIDO2 authentication is the preferred approach, and how organizations can implement phishing-resistant identity security.
No resources found.