'MFA stops phishing'
It is the most common half-truth in security. Multi-factor authentication stops a great deal of phishing, and it does not stop all of it.
A code you can read out is a code you can be talked into relaying, and attackers automate exactly that: you type it into their page, they type it into the real one within seconds. Even where the login is protected, the session token issued afterwards can be stolen. The claim worth making is narrower and still worth making: MFA closes the most common route in. Phishing-resistant MFA closes considerably more.
Checked against the primary source.
