Second factor
A second factor adds to the password something only you have. There are several kinds, and they protect against different things. The film compares them on one attack: a fake site.
Worth watching first:
- Passwords · Security
As text
The same as the films: every shot and its text. You can copy the text and give it to your own assistant along with your question.
Second factor
You can lose a password without doing anything wrong: a leak from one of the sites where you used it is enough. The second factor was invented for exactly that case. Logging in takes two things of different kinds: something you know, the password, and something you have with you, a phone or a key. The password alone is then no longer enough.
The most common second factor is a code by SMS. After the password, the site sends a few digits to your number, and whoever holds the phone confirms the login. It is convenient because nothing needs installing. That is also its weakness: the code is tied to the number, not to the phone. The number can be reissued on another SIM card with a forged request, and then a stranger receives the codes. SMS can also be intercepted in the carrier's network.
An authenticator app works without the carrier. At setup the site and the phone exchange a secret once, and from then on the phone computes the code itself from that secret and the current time. The code is never sent anywhere, so reissuing the SIM card gets an attacker nothing. One limit remains: a person types the code by hand, and so can type it on the wrong site.
Phishing builds on this: luring data out of people with a fake. There are many tricks; one of the simplest is a domain that differs from the real one by a single letter. The person follows a link, sees the familiar login page and enters the password and the code. The attacker's program passes them to the real site at once, while the code is still valid. No method that has you type something by hand protects against this.
A passkey and a hardware key work differently: there is nothing to type. The key signs the login request and is bound to the domain where it was registered. On a domain with one different letter it simply does not work. The protection does not depend on whether the person noticed the fake.
The second factor has a flip side: without the phone or the key, the owner cannot get into the account either. So save the recovery codes right away, on paper or in a password manager, away from the phone. For a hardware key, register a spare and keep it in a different place.
The methods differ in what exactly they protect against. SMS protects against a stolen password. An authenticator app or a push with number matching also protects against a reissued SIM card. A passkey also protects against a fake site. Turn on the strongest method available and start with email, because that is where passwords to all other services get reset.
Next
- Phishing and spoofed addresses · Security