Glossary Security

Multi-factor authentication (MFA)

Multi-factor authentication (MFA) requires two or more kinds of proof to sign in, such as a password plus a code from your phone or a security key.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page

In more detail

The factors are something you know (password), something you have (phone, hardware key) and something you are (fingerprint, face). A stolen password alone is then not enough. App-generated one-time codes (TOTP) beat SMS codes, which can be intercepted; hardware keys and passkeys also resist Phishing. Try a one-time code generator with the TOTP Generator.

Try these tools

See also

  • Glossary Phishing
    Phishing is a scam in which attackers pose as a trusted organisation or person, usually by email or text.
  • Glossary Brute-force attack
    A brute-force attack tries every possible password or key, or a huge list of likely ones, until one works.
  • Glossary Entropy
    In security, entropy measures how unpredictable something is, such as a password or key, usually expressed in bits.
AdSense Placeholder
Slot: footer_leaderboard