What Is Multi-Factor Authentication?

Multi-factor authentication (MFA) requires two or more of the following to verify identity:

Something you know: Password, PIN, security question answer Something you have: Phone, hardware key, smart card Something you are: Fingerprint, face scan, iris scan

By requiring multiple factors, MFA ensures that a stolen password alone is insufficient to access your account. Even if an attacker has your password, they still need your phone, your fingerprint, or your hardware key.

Microsoft reports that MFA blocks 99.9% of automated attacks. Google found that SMS-based MFA blocked 100% of automated bot attacks, 96% of bulk phishing attacks, and 76% of targeted attacks. Hardware security keys blocked 100% of all attack types.

MFA Methods Ranked

From most secure to least:

1. Hardware Security Keys (YubiKey, Google Titan) • Phishing-proof — the key validates the website's identity • Physical device that can't be remotely compromised • Works even if your phone is lost or stolen

2. Authenticator Apps (Google Authenticator, Authy, Microsoft Authenticator) • Time-based one-time passwords (TOTP) • Offline capable — works without cell service • Resistant to SIM-swapping attacks

3. Push Notifications (Duo, Microsoft Authenticator push) • Convenient — just tap "approve" • Vulnerable to MFA fatigue attacks (repeated pushes until the user approves)

4. SMS Codes • Better than nothing, but vulnerable to SIM-swapping • Interceptable by sophisticated attackers • Use only when no better option is available

5. Email Codes • Weakest MFA method — relies on email account security • Use only as a last resort

MFA and Dead Man's Switches

MFA adds a complication to emergency access: even with the password, your family needs the second factor.

Planning for MFA in emergencies: • Store MFA backup/recovery codes in your ZeroLatch vault • Keep a hardware security key in your fireproof safe • Use Authy with multi-device sync so the tokens are accessible from multiple devices • Document which accounts use MFA and which method

Don't let MFA become a barrier to emergency access. The security benefit of MFA is enormous, but only if you plan for scenarios where you can't provide the second factor yourself.