How multi-factor authentication works.
What happens behind a text code, an authenticator app, an approval prompt and a passkey, and why only some of them stop a fake sign-in page.
Multi-factor authentication (MFA) asks for two or more different kinds of proof before it lets you into an account. A text code, an app prompt and a passkey all count, but they work in different ways, and that is why some can be fooled by a fake sign-in page and others cannot. The basics are in Multi-factor authentication: what it is and where to start.
The three kinds of factor
A factor is a kind of proof. There are three: something you know, such as a password or PIN; something you have, such as a phone or a security key; and something you are, such as a fingerprint. A password can be guessed or given away. A phone can be lost or stolen. MFA combines two kinds so that one failure is not enough to open the account.
What happens when you type a code
- A text message code. The service makes up a code and sends it to your phone number. If a criminal talks the phone company into moving your number to their SIM card, the codes go to them.
- An authenticator app code. When you set the app up, the app and the service share a secret. From then on, both combine that secret with the current time and arrive at the same short code, which changes every 30 seconds by default. Nothing is sent to your phone at sign-in, so there is no message to intercept.
Both have the same weak point. You read the code and type it into a web page, and the code has no idea which page it is being typed into. A fake sign-in page can collect your password and your code and pass them straight to the real site. For this reason NIST, the United States standards body, does not treat a hand-typed code as phishing-resistant.
What happens when you approve a prompt
The service sends a notification to the app on your registered phone, and you tap to approve. An attacker who already has the password can send prompt after prompt until one is approved by mistake. Number matching closes that gap: the sign-in screen shows a number and you have to enter it in the app. CISA rates this as resistant to repeated prompts, though still open to a fake sign-in page.
What happens with a passkey or security key
When you set one up, your device creates a pair of matching keys for that one account. The private key stays on the device or the security key. The public key goes to the service. At sign-in, the service sends a random challenge. You confirm with your fingerprint, face or PIN, the device signs the challenge with the private key, and the service checks the signature against the public key.
The key pair is tied to the website it was created for. A look-alike site is a different website, so the device has nothing to offer it and you have nothing to type. That is what phishing-resistant means. CISA describes this method, known as FIDO or WebAuthn, as the only widely available phishing-resistant form of MFA.
What to do with this
- Keep MFA on everywhere. Any form is better than none.
- Use passkeys or security keys where they are offered, starting with email and administrator accounts.
- Where you rely on app prompts, check that number matching is on.
- Keep text message codes for accounts that offer nothing else.
Next, read Are SMS codes good enough for MFA? and When should a business use hardware security keys?
Sources
- Implementing phishing-resistant MFA (CISA) cisa.gov
- SP 800-63B-4: Digital identity guidelines, authentication and authenticator management (NIST) pages.nist.gov
- RFC 6238: TOTP, time-based one-time password algorithm (IETF) rfc-editor.org
- How passkeys work (FIDO Alliance, Passkey Central) passkeycentral.org
- How number matching works in Microsoft Authenticator push notifications (Microsoft Learn) learn.microsoft.com
- Require multifactor authentication (CISA) cisa.gov
- Set up multi-factor authentication: personal cyber security handbook (Australian Signals Directorate) cyber.gov.au