Security › Authentication & Authorization
Multi-Factor Authentication (MFA)
Requiring two or more kinds of proof: something you know, have, or are.
Multi-factor authentication (MFA) asks for proof from more than one category: something you know (such as a password), something you have (such as a security key), or something you are (a biometric used by a device). Two passwords are still one factor because they are both knowledge factors.
MFA can reduce the harm from a stolen or reused password, but factors differ in phishing resistance and recovery risk. A one-time code generated by an authenticator app is better than password-only for many threats, yet users can still be tricked into entering it on a fake site. Passkeys and hardware security keys can bind authentication to the legitimate site and resist that form of phishing. SMS codes are convenient but depend on phone-number security and are not equivalent to a security key.
Design enrollment, replacement, backup, and account recovery as part of the feature. If recovery bypasses every factor with only an email link, attackers may target that weaker route. Offer recovery codes or a documented support process and protect changes to enrolled factors with recent reauthentication.
Backend developers must verify challenges server-side, limit attempts, and bind the challenge to the login session. Frontend developers should explain setup and recovery, preserve accessibility, and avoid logging secrets. See TOTP and passkeys for specific methods.
Operational check: exercise the normal flow, a failed attempt, expiration or revocation, and recovery in tests. Verify that secrets are never included in logs or analytics, and make failure messages useful without revealing account state. Document which service owns the decision so a future client or integration cannot silently bypass it. Changes to identity flows should include a rollback or account-support plan.