# MFA / 2FA

> Multi-factor authentication — proving identity with something you know plus something you have, so a leaked password alone cannot log in.

Passwords leak in every breach and get reused everywhere; the second factor is what keeps a leaked one from being a skeleton key. Factors come in three kinds — knowledge (password), possession (phone, hardware key), inherence (fingerprint) — and MFA requires two different kinds.

The strength ladder matters: SMS codes beat nothing, authenticator apps beat SMS, and hardware security keys (passkeys/WebAuthn) beat both because they cannot be phished in real time. For admin panels and anything touching money or customer data, the top rung is the honest choice.

## Related terms

- https://dfieldsolutions.com/en/glossary/password-hashing.md
- https://dfieldsolutions.com/en/glossary/phishing.md
- https://dfieldsolutions.com/en/glossary/oauth.md

---

Source: https://dfieldsolutions.com/en/glossary/mfa
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
