Passwords leak in every breach and get reused everywhere; the second factor is what keeps a leaked one from being a skeleton key. Factors come in three kinds — knowledge (password), possession (phone, hardware key), inherence (fingerprint) — and MFA requires two different kinds.
The strength ladder matters: SMS codes beat nothing, authenticator apps beat SMS, and hardware security keys (passkeys/WebAuthn) beat both because they cannot be phished in real time. For admin panels and anything touching money or customer data, the top rung is the honest choice.
Related terms
Password hashing
Storing a one-way, salted, deliberately slow fingerprint of each password — so a stolen database is a puzzle, not a list.
Phishing
Tricking people into handing over credentials or clicking the payload — the front door of most breaches, because it attacks the part that cannot be patched.
OAuth
The authorization protocol behind 'Sign in with Google' — lets a service act on your behalf with a scoped token instead of your password.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
