Tech●●●●●Difficulty 3 of 5

Why does a second login step make accounts so much harder to take over, and what comes after passwords?

A stolen password is useless on its own when a second proof is needed, but text-message codes can be hijacked and fake sites can relay them.

▶ Start the story

A password is just something the user knows, and anyone who learns it can use it. Multi-factor authentication changes the deal: access is granted only after the user presents two or more distinct types of evidence. The factors are something you know (a password or PIN), something you have (a bank card, a security token, a phone) and something you are (a fingerprint). It rests on the premise that an unauthorized actor is unlikely to be able to supply all of them. Cash at an ATM already works this way: you need the physical card and the PIN. Accounts with multi-factor authentication switched on are significantly less likely to be compromised.

The common second factor is a code from an authenticator app. It shows a randomly generated, constantly refreshing code, which comes from a time-based one-time password algorithm. A criminal who has only your leaked password cannot produce it.

Three kinds of proof

Something you know

  • A password or PIN
  • Can be guessed, stolen or phished

Something you have or are

  • A phone, a token, a fingerprint
  • An attacker must obtain it too

But not every second factor is equally strong. Codes sent by text message have security concerns: phones can be cloned, and attackers have talked mobile operators into handing out duplicate SIM cards. In May 2017, criminals exploited SS7 vulnerabilities to bypass SMS-based two-step authentication and make unauthorized withdrawals from bank accounts.

Fake sites can beat codes too. An impostor site can relay your login to the real service in real time, passing along the code you type. That is one reason behind a newer idea: passkeys. Instead of a secret you type, your device holds a private key and proves it can solve a challenge from the site, without ever sending the key. Because the device only offers a credential registered for the real website, a look-alike site is not offered it, which makes passkeys resistant to some phishing attacks.

Quiz me

0/3

  1. 1.Why are codes sent by text message a weaker second factor?
  2. 2.Why can an impostor site defeat a typed one-time code?
  3. 3.Why does a passkey resist look-alike websites?

Recap

Text codes can be intercepted through the phone network, a typed code can be relayed by a fake site, and a passkey is only offered to the site it was registered for.

💡 A trick to remember it · Know, have, are: three kinds of proof, and a passkey is the key that never leaves your device.

Surprising fact · In 2017 criminals bypassed text-message codes by exploiting phone-network weaknesses.

Sources (5)

No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.

  1. [1]Multi-factor authentication · Wikipedia
  2. [2]Time-based one-time password · Wikipedia
  3. [3]Passkey · Wikipedia
  4. [4]WebAuthn · Wikipedia
  5. [5]Phishing · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗