Sunday 12 July 2026 17:32:38 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

WIKICROOK

Phishing-resistant MFA

Multi-factor authentication designed to resist token theft and social engineering, often using stronger login methods than SMS codes.

Phishing-resistant MFA is multi-factor authentication that is designed to stay secure even when an attacker can trick a user into entering credentials on a fake site or can steal a one-time code. It usually relies on methods such as FIDO2/WebAuthn security keys, device-bound passkeys, or certificate-based logins that cryptographically verify the real service before completing authentication.

It matters because many attacks bypass weaker MFA by stealing SMS codes, replaying push approvals, or using adversary-in-the-middle phishing pages to capture session tokens. Phishing-resistant MFA reduces those risks by binding the login response to the legitimate domain and the user’s device. In real defenses, it is used to protect email, VPN, admin portals, and remote access tools. It is especially valuable when attackers use social engineering, credential theft, or token replay to move from an initial compromise into broader access.

← WIKICROOK index