Lessons · IT support · MFA
MFA: something you know plus something you have
Multi-factor authentication asks for a second proof after the password: a code from a phone, a tap on an app, a hardware key. A stolen password on its own is then not enough to sign in, which is the single biggest reason phishing fails when it does.
Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.
What it is for
A user typed their password into a fake sign-in page on Tuesday. On Wednesday morning their phone buzzes with a sign-in prompt they did not ask for, from a city they are not in. They press 'no'. The attacker has the password and cannot use it. Without the second factor, Wednesday morning is a compromised mailbox and a security incident.
How to think about it
Enrol every account that can be enrolled, and treat an unexpected prompt as evidence, not noise: it means the password is known to somebody who is not the user. Move a user to a new phone by verifying identity, removing the old device, enrolling the new one, and testing a sign-in while they are with you. Give them backup codes, and tell them where a code is never typed: into a page that asked by email.
Worked example
Password entered on a fake page Tuesday 16:10One factor is now in somebody else's hands.
Wednesday 08:30: sign-in prompt on the user's phone from another city; user presses denyThe second factor did its job. The password alone opened nothing.
Reset the password anyway; report to security with the time and the location on the promptThe prompt is evidence of the attempt. The password is changed because it is known, not because it worked.
Note: 'MFA denied an attempt at 08:30; password reset; security informed'The ticket says what happened, what stopped it, and who was told.
Your turn
Write the thing a stolen password cannot do on its own when MFA is on.
With MFA, a stolen password alone cannot
Solve one, graded on the server
The trap
Approving a prompt to make it stop. An attacker who has the password will send prompts until one is approved out of annoyance. A prompt you did not cause is always 'no', and always a ticket.