We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Food for thought if you use passwords + 2FA/MFA (and who doesn't :-)
Options

TMSG
Posts: 228 Forumite

in Techie Stuff
The MFA You Trust Is Lying to You – and Here's How Attackers Exploit It
A bit OTT but an interesting read. I fully agree that SMS/text is (or should be) dead -- I avoid organisations which still use that. But I am not convinced that 2FA/MFA is yet on its last leg although it's clearly not a solution for the future. Alas, as long as the passkeys crowd doesn't get the interoperability solved in an easy and reliable manner, I don't really see much choice.
A bit OTT but an interesting read. I fully agree that SMS/text is (or should be) dead -- I avoid organisations which still use that. But I am not convinced that 2FA/MFA is yet on its last leg although it's clearly not a solution for the future. Alas, as long as the passkeys crowd doesn't get the interoperability solved in an easy and reliable manner, I don't really see much choice.
1
Comments
-
The article is sponsored by Token, a vendor selling biometric FIDO2 devices. It exaggerates legacy MFA’s weaknesses to promote Token’s products, ignoring that MFA effectiveness depends on implementation, user training, and layered security, not just hardware1
-
Vitor said:The article is sponsored by Token, a vendor selling biometric FIDO2 devices. It exaggerates legacy MFA’s weaknesses to promote Token’s products, ignoring that MFA effectiveness depends on implementation, user training, and layered security, not just hardwareDrinking Rum before 10am makes you
A PIRATE
Not an Alcoholic...!1 -
Oh sure, the proposed two Token methods are not why posted this (I didn't even mention them in my OP).
The point is more that I've been (and still am) trying hard to get people onto non-SMS 2FA/MFA where possible and also looking for cases where an account was "hacked" despite a strong password and 2FA/MFA. So far, at least in my relatively small circle of people there's been no such case but apparently this happens more often than I (probably naively?) assumed.
2FA/MFA clearly can't be the final word, not least because it offers no protection at all against perfectly replicated phishing sites. This automatic protection is one of the passkeys features I really like. Unfortunately, passkeys have other problems though I readily accept that most will, in due course, be rectified.
0 -
I'm experiencing more bank's web sites showing a QR code after inputting username. You open the mobile banking app using a biometric, which then uses the phone’s camera to scan the QR code. The app communicates back to the bank, which logs you in on the desktop automatically.
It's a clever system based on the same principles as Passkeys but more comprehensible to Joe User, while is resistent to phishing
I tried the full-fat solutoin of FIDO2 keys (the one Google sells) but the annoyance factor was off the scale!0 -
Basically another Yubico clone.
There is no such thing as absolute security. MFA and 2FA can be compromised by many methods. You can even buy the devices on Amazon.
Hence it's always good cybersecurity practice to not rely on any one solution for everything1 -
Does not matter what 2FA you use whether it's a text or an app, the problem is the user.
Scammers will say there is a problem and do not use the fingerprint option or whatever and that they need
to request a code instead where they then share the code with the scammers.Censorship Reigns Supreme in Troll City...0 -
forgotmyname said:Does not matter what 2FA you use whether it's a text or an app, the problem is the user.
And social engineering is probably a bigger problem for end users than fixing known vulns as this is normally taken care of by the OS provider.
0
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 350.8K Banking & Borrowing
- 253K Reduce Debt & Boost Income
- 453.5K Spending & Discounts
- 243.8K Work, Benefits & Business
- 598.6K Mortgages, Homes & Bills
- 176.8K Life & Family
- 257.1K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards