Last time I wrote about password managers and promised to come back to why a password alone, however strong and unique, is not enough to be the only barrier between an attacker and your account. Today we look at that second layer: two-factor authentication, and why not all two-factor authentication is created equal.
Why a password alone is not enough
Even a perfect password has one weakness: you can type it into a fake page yourself without noticing. A fraudulent email, a counterfeit sign-in page, a moment’s inattention, and the password is gone, however long and random it was. A second layer of authentication is insurance for exactly that moment: even if the password leaks, the attacker still cannot get in without the second factor. The trouble is that not all second factors are equally strong, and that is today’s subject.
Four levels, from weakest to strongest
An SMS code is the most common option, but also the weakest. The attacker does not need to crack anything technical. They simply call your mobile operator, pose as you and persuade the operator to move your number to another SIM card. This is known as SIM swapping, and it has become a genuine business, aimed mainly at people likely to yield a bigger payoff. Jack Dorsey, then head of Twitter, lost control of his own account, with its four million followers, for a few dozen minutes in exactly this way. The attackers only needed control of his number to post from his account, with no password required. And that was just one of the publicly known cases. Once an attacker controls your number, your SMS codes go to them instead of you, and from there it is a short step to taking over your email, your bank account or your cryptocurrency account.
Authenticator apps, such as Google Authenticator or Aegis, are a step up. The code is generated on your device itself rather than sent by SMS, so SIM swapping does not work against them. But they have a different weakness: if an attacker lures you to a convincing copy of a sign-in page, they can pass the code you enter on to the genuine page in real time. I know of one exceptionally inventive case in which the attacker combined a fake sign-in page with a phone call, even using AI to imitate the voice of a real member of the IT staff, and persuaded an employee to read the verification code out loud. Apps on their own do not protect against this type of attack. They only protect against the code being diverted through someone else’s SIM card.
Push notifications, where an app simply asks “Is this really you?” and you tap yes, are convenient, but they have a weakness of their own, known as MFA fatigue. An attacker who so far knows only your password fires off dozens of sign-in requests in a row until you are irritated enough to approve one just to make them stop. That is exactly how attackers got into the internal network of one of the world’s largest ride-hailing apps in 2022. They bombarded an employee with approval requests, and when that did not work, they messaged him directly on WhatsApp, claiming to be IT support and telling him to just approve it, or the requests would keep coming. The employee did. A single mistake by a single person was enough.
A hardware security key is the fourth and strongest level, and the reason is elegant. When you sign in, the browser gives the key the real address of the page, and the key will only sign for the site it was registered with. A fraudulent copy of the page, however convincing, has a different address, and the key simply refuses to respond to it. However thoroughly a person is deceived, and however convincing the voice on the phone, it is the device itself that decides whether the sign-in goes ahead, based on the real address of the page. That is what reduces the scope for classic phishing to a minimum. The latest development in this direction is passkeys, which I mentioned last time in the article on password managers. They work on the same principle, except that they replace the password altogether rather than being just an extra second step.
Hardware security keys: which ones and how many
Common options include the YubiKey and Nitrokey ranges, available with USB-A, USB-C or NFC. Before you choose, check which standards they support and whether they are compatible with your devices and accounts. One important rule also applies: get two keys. Carry one with you and keep the other somewhere safe as a backup, because recovering an account after losing your only key can be difficult.
Why wealthy people are a particular target
The mechanism is always the same: a phone number is the key to getting round SMS verification, and the higher the victim’s profile, the bigger the reward for a successful attack and the more time the attacker is willing to invest in persuading a particular operator. For clients facing a higher level of exposure, I recommend two additional steps. First, phone your operator and ask whether it offers extra protection against your number being transferred to another SIM card. Some operators do, although they often do not advertise it, so ask directly. Second, wherever possible, move away from SMS to an authenticator app or straight to a hardware security key. This greatly reduces the value of your phone number as a second factor. And wherever the service allows it, remove your phone number as a backup recovery method too; otherwise it remains a back door.
Backup codes: where to keep them
When you turn on two-factor authentication, most services also give you a set of one-time backup codes in case you lose both your phone and your key at the same time. Print them and store them physically separate from the phone and the key you use to sign in, ideally wherever you keep your passport or other important documents. What you must not do is photograph them into your phone’s gallery. The gallery syncs to the cloud, and if an attacker ever gets hold of your phone or your cloud account, they immediately get the key to the second door you were trying to protect.
“A password is the lock on the door. The second factor is an extra bolt. But even the strongest bolt must be properly anchored, or it simply hangs on the door and holds nothing.”— Robert Václavík




