InspeticaOpen the daily feed

Cyber Safety · 55 sec

Not All MFA Resists Phishing Equally

A second login step helps, but some methods can still be copied into a fake site.

  1. Codes can be relayed

    An attacker-controlled login page can capture a password and ask the victim to enter a one-time code while it is still valid.

  2. Prompts can be abused

    Repeated push approvals can exploit fatigue or confusion when the prompt is not tightly bound to the login the user started.

  3. Stronger methods bind

    FIDO security keys and compatible phishing-resistant sign-ins verify the real site instead of sending a reusable secret.

Using MFA is important, but choosing the strongest method available reduces dependence on spotting a convincing fake page.

Use a phishing-resistant security key or FIDO-based sign-in for important accounts when available.

Test your recall

Which action best applies “Not All MFA Resists Phishing Equally”?

  • Use a phishing-resistant security key or FIDO-based sign-in for important accounts when available. — correct
  • Approve repeated prompts until the notifications stop.
  • Reuse the same one-time code on another site if the first login fails.

Using MFA is important, but choosing the strongest method available reduces dependence on spotting a convincing fake page.

EvergreenLast verified 2026-08-14

Sources