Skip to content

Archive

MFA

2 articles
Cybersecurity 10 Sep 2026 12 min read

Treat MFA Recovery Codes as Real Credentials

Multifactor authentication can fail for ordinary reasons: a phone is lost, a hardware key breaks, or a device is replaced before an authenticator is migrated. Recovery codes give users a way back into an account without asking support staff to improvise an identity check. That convenience creates a security boundary of its own. If a recovery code can bypass the normal second factor, anyone who obtains that code may be able to do the same. A recovery system that is easier to attack than the authentication it replaces can quietly become the preferred path into the account.

Cybersecurity 10 Sep 2026 9 min read

Design Push MFA to Resist Approval Fatigue

A push notification can make multi-factor authentication feel effortless: enter a password, tap Approve on a registered device, and continue. The same convenience creates a problem when the approval prompt does not require the user to prove which login they are approving. If an attacker obtains a password and can repeatedly trigger MFA requests, the legitimate user may receive prompts they did not initiate. A tired, distracted, or confused user may eventually approve one. This is commonly called MFA fatigue or push fatigue.