Phishing-resistant MFA

Not all second factors are equal, and the difference is whether the thing can be tricked into helping.

A code from an app or a text can be read out, typed into a fake site and relayed by the attacker to the real one within seconds. It works perfectly, just for somebody else. A phishing-resistant factor, a passkey or a hardware key, is tied to the real website's address and checks it before responding. Shown a convincing fake, it simply does not answer. That is a different kind of protection from a factor that answers whoever asks.

Checked against the primary source.

More on Identity & access