At a glance
Passwords alone are no longer enough to secure your accounts: multi-factor authentication, or MFA, is the new standard.
Passwords alone are no longer enough to secure your accounts: multi-factor authentication, also known as MFA, is the new standard. Here's why.
To access our various online accounts every day (email, social media, online shops, etc.), we use dozens of passwords. Unfortunately, in an increasingly digital world, passwords are becoming more and more vulnerable to cyberattacks.
It's therefore necessary to add other security measures to access our online accounts. That's why it's recommended to enable multi-factor authentication whenever possible.
Let's take a look at how MFA works, why it's important to use it, and what its limitations are too.
Multi-factor authentication
Multi-factor authentication refers to a security measure. It involves adding, on top of your password, at least one additional verification method (a code sent by text message or email, for example) to log in to an account.
In some cases, individuals can decide to enable multi-factor authentication themselves to access an account or online service. In other cases, it's the online service that requires this method. From a security standpoint, in any case, it's recommended to enable this feature whenever it's offered to you.
MFA is sometimes incorrectly referred to as "two-factor authentication". In some cases, security processes require more than two authentication steps.
What are the different MFA methods?
There are three main methods of multi-factor authentication. You authenticate yourself:
- With something you know: a password, a PIN code, for example.
- With something you have: a code sent by email or text message with a limited lifespan, a rotating code obtained via a mobile app, etc.
- With a biometric feature: a fingerprint, facial, voice or retinal recognition, etc.
Examples of multi-factor authentication
Multi-factor authentication can take different forms. It consists of at least two authentication methods. Here are a few examples:
- Password + one-time code sent by text message
- Password + push notification
- Password + rotating code available on an app
- Password + biometric fingerprint
It's even possible to combine three different authentication factors, for example a password followed by a code received by text message and then a fingerprint. This makes things even harder for hackers.
What are the benefits of MFA?
Making up for the vulnerability of passwords
Very often, people use the same password for different accounts. If that password leaks, several accounts can therefore be compromised. MFA provides an answer to this kind of problem.
With multi-factor authentication, even if your password is compromised, access to your account isn't possible unless the hacker also has the other authentication methods.
Making cyberattacks more difficult
By using several authentication factors (and, if possible, of different types), attacks become longer and more difficult for hackers. They simply have to clear several hurdles to carry out their attacks.
Many cybersecurity experts even consider MFA to be an essential security measure.
The limitations of multi-factor authentication
"All-digital" doesn't suit everyone
Enabling MFA generally means having a smartphone… and knowing how to use it. And if you're anti-smartphone, don't feel the need to own one, or simply can't afford one, going through authentication steps can sometimes turn into a real headache.
Notifications can fool you
Do you tend to accept the various push notifications you receive without necessarily being suspicious? Be careful, and think carefully about the constraints before choosing one multi-factor authentication method over another.
Hackers and bypassing MFA
Hackers are getting better and better at bypassing MFA. Enabling MFA on accounts (wherever possible) shouldn't give you a false sense of security or invulnerability.
After obtaining a victim's username and password, hackers can, for example, convince them to send over the verification code they received by text message. Fingerprint readers can also be bypassed.
MFA solutions sometimes have vulnerabilities that hackers are quick to exploit. In short, no method is completely foolproof.
While strongly encouraged, setting up MFA should come on top of other security measures. Creating long, complex passwords that are different for each account is, for example, good practice when it comes to "cyber hygiene".
Article written in collaboration with We are the Words.



