Cyber Safety · 55 sec
Not All MFA Resists Phishing Equally
A second login step helps, but some methods can still be copied into a fake site.
The useful idea
- Codes can be relayed
An attacker-controlled login page can capture a password and ask the victim to enter a one-time code while it is still valid.
- Prompts can be abused
Repeated push approvals can exploit fatigue or confusion when the prompt is not tightly bound to the login the user started.
- Stronger methods bind
FIDO security keys and compatible phishing-resistant sign-ins verify the real site instead of sending a reusable secret.
Why this matters
Using MFA is important, but choosing the strongest method available reduces dependence on spotting a convincing fake page.
Try this
Use a phishing-resistant security key or FIDO-based sign-in for important accounts when available.
Test your recall
Which action best applies “Not All MFA Resists Phishing Equally”?
- Use a phishing-resistant security key or FIDO-based sign-in for important accounts when available. — correct
- Approve repeated prompts until the notifications stop.
- Reuse the same one-time code on another site if the first login fails.
Using MFA is important, but choosing the strongest method available reduces dependence on spotting a convincing fake page.