Skip to main content
PASSWORD-SECURITY5 MIN READ

Know where passwords stop helping and phishing-resistant factors start

Explain why strong passwords still need phishing-resistant authentication on higher-risk accounts.

Passwords and phishing solve different problems. A password can be long, unique, and manager-generated and still be stolen at the moment of sign-in if a user enters it into a convincing fake page. That is why authentication guidance talks about assurance levels rather than only password rules. The more damaging the account, the less acceptable it is to depend on a single reusable secret. Multi-factor authentication raises the bar because the attacker needs more than the password. But not all second factors are equal. Codes that can be intercepted or socially engineered are better than nothing, yet they are still…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us