Multi-Factor Authentication: More Than Just Passwords

Imagine a bank vault.

Having a key might not be enough to open the door – perhaps you also need a PIN and a palmprint before the vault will open. Each item provides a different piece of evidence that you are authorised to enter.

This is the basic idea behind Multi-Factor Authentication (MFA).

Instead of relying on a single method to prove someone’s identity, MFA requires two or more different authentication factors.

The important word here is different.

Using two passwords isn’t really MFA – both passwords are something you know

Using a password and a physical security key is using two dissimilar things – Something you know and something you have

Using a password and a fingerprint is also MFA – something you know and something you are

Using a password and a one-time code from an authenticator application is also MFA – something you have, and something given to you by a trusted entity

The goal is straightforward:

If one authentication factor is compromised, the attacker still needs another factor.

What Is Multi-Factor Authentication?

Authentication is the process of establishing that someone, or something is who or what it claims to be.

Traditionally, this has often meant a username and a password

Usernames are commonly public knowledge – so the only thing protecting the access is the password

The problem is that passwords can be:

  • Guessed
  • Brute-forced
  • Phished
  • Reused
  • Stolen
  • Leaked
  • Captured by malware
  • Shared with other people

If the password is the only thing protecting an account, stealing that password may be enough to take over the account.

MFA introduces another barrier – An attacker who has stolen the password still needs the second factor.

The Three Main Authentication Factors

Authentication factors are generally divided into three broad categories.

1. Something You Know

Examples include:

  • Password
  • PIN
  • Passphrase
  • Security question

2. Something You Have

This is a physical or digital object that you possess.

Examples include:

  • Security keys
  • Smart cards
  • Hardware tokens
  • Mobile phones
  • Authenticator applications
  • One-time password generators

This is particularly interesting because it introduces something that is harder for an attacker to obtain remotely.

3. Something You Are

This is something inherent to you – normally a biometric characteristic.

Examples include:

  • Fingerprint
  • Face
  • Iris
  • Voice

Biometrics can be extremely convenient because you don’t have to remember or carry them.

However, they have an important limitation:

You can’t change your fingerprint in the same way that you can change a password.

This makes biometric information something that needs to be handled carefully.

MFA involves a combination of two or more of these different properties

Password + Authenticator App

One of the most common forms of MFA combines a password with a code generated by an authenticator application.

The application generates a temporary code – E.g. 482 913

The code changes at regular intervals

Even if an attacker knows the password, they most likely do not have access to the authenticator application or the secret used to generate the codes in the application.

An Authenticator app showing one-time codes

Time-Based One-Time Passwords

A common technology behind authenticator applications is a Time-Based One-Time Password (TOTP).

The application and the authentication server share a secret which they use, together with the current time to generate a temporary code.

The resulting code is normally valid for only a short period (60 seconds is common)

This makes it considerably more difficult for an attacker to reuse a captured code at a later time

Push Notifications

Another common approach is a push notification.

Instead of asking the user to type a code, the authentication service sends a notification to the users registered device and asks the user to confirm the login.

An MFA push notification

This can be convenient, but it introduces another potential attack:

MFA fatigue.

MFA Fatigue

Imagine an attacker has obtained someone’s password and repeatedly attempt to log in to their account. If push notifications are part of the MFA process, the victim’s phone receives:

Sign-in request
[Approve] [Deny]

Then another:

Sign-in request
[Approve] [Deny]

Then another.

And another.

And another…

Eventually the user might approve the request simply to make the notifications stop. The user doesn’t realise that they have just granted the attacker access to their account.

This is known as MFA fatigue or MFA push bombing.

The lesson is important – MFA improves security, but the way MFA is implemented matters.

Some organisations therefore use additional controls such as:

  • Number matching
  • Login context
  • Device information
  • Location information
  • Phishing-resistant authentication

Physical Security Keys

One of the strongest and most interesting forms of MFA involves a physical security key.

Examples of these include hardware security keys such as YubiKeys.

A Yubikey

The key is a small physical device that can be used to authenticate to a service. the device can often be connected to a device via USB or via NFC.

The key can use standards such as FIDO2/WebAuthn to provide strong, phishing-resistant authentication.

Why Are Security Keys So Interesting?

A conventional MFA code can potentially be entered into a convincing fake website to trick users

A modern phishing-resistant security key works differently – The authentication process is cryptographically tied to the legitimate website’s origin.

The key doesn’t simply reveal a reusable secret that the attacker can copy.

If the user is tricked into visiting something like https://fake-example.com, as opposed to https://real-example.com, then the security key can recognise that the domain origin is wrong and refuse to authenticate with it.

This makes phishing-resistant authentication significantly stronger than simply adding another code to a password.

Smart Cards

Another physical authentication mechanism is a smart card.

A smart card contains an RfID chip that can store credentials or cryptographic keys.

Smart cards have traditionally been used in environments such as:

  • Government
  • Defence
  • Enterprise networks
  • Secure facilities
  • Identity systems

The physical card represents something you have, while the PIN represents something you know.

Biometrics

Biometric authentication uses some type of characteristic of the individual such as a fingerprint, palm-print, iris patterns, or facial features.

Biometrics are particularly common in modern smartphones and laptops, but they have some important limitations.

A password can be changed.

A biometric characteristic generally cannot.

If a password is compromised, you can simply reset the password to something different

But you can’t simply replace your fingerprint, or your iris.

Biometric systems also need to consider:

  • False positives
  • False negatives
  • Spoofing
  • Sensor quality
  • Privacy
  • Storage of biometric information
  • Legal requirements

For these reasons, biometric authentication needs to be carefully designed.

Biometrics and Local Device Authentication

An important distinction is where the biometric information is processed.

Modern devices can often use the biometric data to unlock a protected credential locally, rather than sending the user’s fingerprint or face image to every service they access.

This can be a much better privacy and security architecture than distributing raw biometric information to every application.

Location as an Authentication Signal

Location can sometimes be used as an additional contextual signal when using MFA

For example, lets imagine the scenario where the user (Alice) is logging on to the payroll system via her corporate laptop from her home location in the UK at 09:15

User:       Alice
Device:     Company laptop
Location:   UK
Time:       09:15
Request:    Access payroll

The system could determine that this is consistent with expected behaviour of this user.

Compare that with the user (Alice) logging on to the payroll system via an unknown device from Spain at 03:17

User:       Alice
Device:     Unknown
Location:   ES
Time:       03:17
Request:    Access payroll

This could trigger additional authentication requests or deny access.

Location is generally better thought of as contextual information rather than one of the three classic authentication factors.

It can strengthen an authentication decision without replacing a proper authentication factor.

Behavioural Authentication

Systems can also examine behavioural characteristics such as:

  • Typing patterns
  • Mouse behaviour
  • Device usage
  • Normal login patterns

Again, these can be useful signals, but they shouldn’t automatically be confused with the traditional three authentication-factor categories.

This is often described as adaptive or risk-based authentication.

MFA and Single Sign-On

MFA is often combined with Single Sign-On (SSO).

Instead of authenticating separately to every application, the organisation can use a central identity provider that once authenticated to (using MFA) can provide tokens for each separate service the user is allowed to access.

This can improve both security and usability.

Instead of managing authentication separately across dozens of applications, the organisation can centralise it.

MFA Doesn’t Replace Good Passwords

MFA significantly reduces the consequences of a stolen password – but passwords still matter.

MFA is an additional layer, not an excuse to abandon good password practices where passwords are still used.

MFA Can Be Bypassed

MFA is powerful, but it isn’t a magic bullet. Attackers have developed techniques specifically designed to get around it.

Phishing

Traditional phishing can attempt to capture a password and an MFA code. The attacker can then attempt to use the information against the legitimate service.

This is one reason phishing-resistant MFA is increasingly important.

Session Cookie Theft

Suppose an attacker manages to steal an already authenticated session. The attacker may be able to use the session without performing the login process again.

MFA protected the login, but the attack happened after authentication.

This demonstrates why MFA needs to be combined with other controls such as:

  • Session management
  • Device security
  • Conditional access
  • Token protection
  • Monitoring

MFA Fatigue

As discussed earlier, push-based MFA can sometimes be abused by repeatedly sending authentication requests. The attacker hopes that the user eventually approves one.

The defence includes:

  • Number matching
  • User education
  • Risk-based policies
  • Stronger authentication methods
  • Phishing-resistant MFA

Social Engineering

An attacker may simply try to persuade the victim to reveal or approve the second factor.

For example – “I’m from IT. We’re fixing your account. Can you read me the code you just received?”

The technology may be working perfectly, but here. the attacker is attacking the human being using the technology.

This is why security awareness remains important even when MFA is deployed.

SIM Swapping

SMS-based MFA can be vulnerable to SIM swapping.

An attacker may socially engineer or otherwise compromise a mobile provider’s processes to transfer a victim’s telephone number to another SIM.

The attacker can then potentially receive the SMS message with the MFA code

This doesn’t mean SMS MFA provides no value – It is generally better than having no additional factor at all.

But stronger alternatives such as authenticator applications, hardware security keys and phishing-resistant authentication can provide better protection against many attacks.

Read this page for more detail on SIM swapping.

The Practical Approach

Organisations implementing MFA should consider the following:

Start with important accounts

Prioritise:

1. Privileged administrators
2. Remote access
3. Email
4. Cloud services
5. Financial systems
6. Sensitive applications
7. All remaining users

Prefer strong factors

Where practical, consider:

  • Security keys
  • Passkeys
  • Authenticator applications
  • Smart cards
  • Biometrics combined with secure credentials

Plan for lost devices

What happens if someone loses their:

  • Phone?
  • Security key?
  • Smart card?

There needs to be a secure recovery process.

Protect the recovery process

This is particularly important.

If an attacker can simply phone the help desk and say:

“I’ve lost my MFA device. Can you disable MFA?”

then the attacker may simply target the recovery process instead.

Account recovery must be protected as carefully as the authentication process itself.

MFA as a Security Control

MFA is primarily a preventive security control – It attempts to prevent unauthorised users from successfully authenticating.

But MFA can also contribute to detective controls – For example, repeated failed MFA attempts can generate alerts which could indicate an attempt to force MFA fatigue against users.

So, as with firewalls and access controls, one technology can contribute to multiple security-control categories.

In Summary

Multi-Factor Authentication (MFA) requires two or more different authentication factors before access is granted.

The three traditional factor categories are:

Something You Know

  • Passwords
  • PINs
  • Passphrases

Something You Have

  • YubiKeys and other security keys
  • Smart cards
  • Mobile phones
  • Authenticator applications
  • Hardware tokens

Something You Are

  • Fingerprints
  • Facial recognition
  • Iris recognition
  • Other biometric characteristics

MFA can significantly reduce the risk associated with stolen passwords, but not all MFA is equally strong.

SMS codes and push notifications can provide useful protection, but stronger approaches include phishing-resistant security keys and passkeys.

Attackers can still attempt to bypass MFA through:

  • Phishing
  • MFA fatigue
  • Social engineering
  • Session-token theft
  • SIM swapping
  • Compromised devices
  • Weak account-recovery processes

MFA should therefore be part of a broader security architecture incorporating:

  • Strong authentication
  • Least Privilege
  • Access Controls
  • Zero Trust
  • Defence in Depth
  • Monitoring
  • Secure account recovery

The most important distinction to remember is that MFA doesn’t make an account impossible to compromise. What it does is make a stolen password no longer enough.

And in cybersecurity, making an attacker’s job significantly harder can be an extremely valuable security control in its own right.