Not all factors are created equal. Or why verification codes aren’t enough.
Multi-factor authentication (MFA) is now a common protection against password misuse. When logging in, we are used to entering not only a password but also one-time verification codes from email, SMS, or an app. However, this method has a critical weakness. In this article, we reveal the vulnerabilities of verification codes and show how to ensure security without sacrificing convenience.