Skip to content

Archive

Multi-Factor Authentication

5 articles
Cybersecurity 11 Sep 2026 10 min read

Treat Recovery Codes as One-Time Authentication Secrets

Multi-factor authentication can lock out a legitimate user when a phone is lost, an authenticator is reset, or a security key is unavailable. Recovery codes give the user a controlled fallback. The risk is that this fallback can quietly become an easier way into the account than the authentication method it is supposed to recover. A recovery code is not just a convenience string. It is an authentication secret that may let someone bypass an unavailable factor. If an attacker obtains a valid code and the application accepts it, the application cannot tell that the person presenting it is not the legitimate user.

Cybersecurity 09 Sep 2026 10 min read

Design Push MFA to Resist Prompt Fatigue

Push-based multi-factor authentication can make sign-in convenient: after a password is accepted, the user receives a prompt on a trusted device and approves the attempt. The weakness appears when the prompt itself becomes easy to approve without understanding what it represents. If an attacker obtains a password and can repeatedly trigger approval requests, the legitimate user may eventually approve one because the prompts are confusing, disruptive, or mistaken for a request they initiated. The second factor still exists, but its security value has been reduced to a repeated yes-or-no question.

Cybersecurity 08 Sep 2026 9 min read

Treat Recovery Codes as One-Time Authenticators

Multi-factor authentication can fail for ordinary reasons: a phone is replaced, a hardware authenticator is lost, or an authenticator application becomes unavailable. Recovery codes give a user a backup path, but that path also becomes part of the authentication system. If a copied recovery code keeps working after it has been used, anyone who obtained the copy may be able to reuse it later. The useful mental model is therefore simple: a recovery code is a one-time backup authenticator, not a reusable emergency password. The server should accept a valid code once, consume it as part of that successful authentication, and reject the same code afterward.

Cybersecurity 07 Sep 2026 10 min read

Treat Authenticator Enrollment as an Account-Control Change

Adding an authenticator can look like an ordinary settings change. It is not. A newly enrolled security key, authenticator app, or other login method may be accepted during future sign-ins, long after the session that created it has ended. That makes enrollment an account-control change: it changes which evidence the system will trust as proof of the user’s identity. If a stolen session is enough to add a new authenticator, an attacker may turn temporary session access into a durable way to return later.

Cybersecurity 03 Sep 2026 8 min read

Choose Multi-Factor Authentication by Threat Model

Multi-factor authentication (MFA) reduces the damage caused by stolen passwords, but not every second factor provides the same protection. A one-time code, a push approval, and a hardware-backed credential all add another authentication step, yet they behave differently under phishing, malware, social engineering, and account recovery attacks. The useful question is therefore not simply whether MFA is enabled. It is whether the authentication method resists the threats that matter for the account being protected.