Glossary

Phishing-resistant MFA

Phishing-resistant MFA is multi-factor authentication that a phishing attack cannot defeat. It binds the sign-in to the real site and the real device. So there is no code for an attacker to steal.

On this page
  1. What is phishing-resistant MFA?
  2. Why is normal MFA not phishing-resistant?
  3. What makes MFA phishing-resistant?
  4. What are examples of phishing-resistant MFA?
  5. How does SenseCrypt give phishing-resistant sign-in?
  6. Frequently asked questions

What is phishing-resistant MFA?

Phishing-resistant MFA is multi-factor authentication that a phishing attack cannot defeat. The bar is specific, and it is not about how many factors you ask for. It is about whether an attacker who controls the page a user is looking at can still walk away with a working credential.

Real-time proxy phishing raised that bar. A modern kit relays each field to the real site as the user types it, so a second factor that a person can read out is captured and spent within seconds. Phishing resistance means there is nothing to relay.

Why is normal MFA not phishing-resistant?

Most MFA in production still ends with a person deciding to hand something over: a code to type, or a prompt to accept. Both decisions can be steered by a convincing page or a well-timed phone call.

This is not a training failure. If the user is able to move the proof to a stranger, the method has a design gap, and no amount of awareness work closes it.

One-time codes can be relayed

A proxy site shows a real-looking form, collects the code, and spends it on the real site before it expires. The user sees an ordinary sign-in and the attacker gets a session.

Tap-to-approve invites fatigue

An approval prompt carries little context, so a user who is busy or half asleep accepts it. Push bombing works because saying yes is cheaper than working out why the prompt appeared.

SMS has a carrier attached

A SIM swap or a redirected number moves the second factor to somebody else without touching the account. You are trusting a telecom process that you do not control.

What makes MFA phishing-resistant?

Take away everything a fake site could capture, and the attack has nowhere to land. The methods that qualify share the same few properties, whatever a vendor calls them.

Notice that none of these properties ask the user to be careful. That is the point. The protection holds even when the person is fooled.

No value the user can pass on

If there is no password and no code in the flow, a fake page has nothing worth asking for. This single property does most of the work.

The proof is bound to one device

The credential lives on registered hardware and cannot be used from anywhere else. A captured message replayed from an attacker's machine fails.

The approval names the relying party

The user approves a request that states which application asked for it, on their own device, away from the browser under attack.

Origin or channel binding

A passkey checks the site domain before it signs. A backchannel flow keeps the approval off the phished channel entirely. Either way the wrong site gets no answer.

What are examples of phishing-resistant MFA?

Standards bodies name a short list, and it is short for a reason. Each method on it removes the shared secret rather than protecting it better.

If a method is not on a list like this, treat it as MFA that raises the cost of an attack, not MFA that stops one.

  • FIDO2 and passkeys: a key pair bound to the site domain.
  • Smart cards and PIV: a certificate on a physical card, unlocked with a PIN.
  • On-device biometrics that unlock a device-bound key.
  • Backchannel approval on an enrolled device, where the user never sees a code.

How does SenseCrypt give phishing-resistant sign-in?

SenseCrypt removes the secret instead of protecting it. Sign-in has no password and no shared code, so there is no field on a phishing page worth building. The user looks at the camera on their own enrolled device, and the face match runs there.

One one-time PIN exists in the product, and it has one job: binding a new device. It is emailed, and also sent by SMS when a mobile number is on file. It is never part of a routine sign-in.

Nothing to type, nothing to read out

Sign-in asks the user for no value at all. The credential an attacker wants is never rendered in a form the user could forward.

The ceremony runs on a bound device

Face capture and matching happen on the phone the user enrolled. A session started on an attacker's machine cannot borrow it.

CIBA push starts a face check

The backchannel prompt offers no approve button. It opens a device-bound face ceremony, so push fatigue has nothing to exploit.

The face token is single use

Each sign-in spends one patent-pending face token, not an image and not a template. A copy captured in transit is already dead.

Frequently asked questions

Is OTP phishing-resistant?

No. A user can type a one-time password (OTP) into a fake site. An attacker can then replay it. OTP is MFA, but it is not phishing-resistant.

Is push-notification MFA phishing-resistant?

A tap-to-approve push is not phishing-resistant. An attacker can send many prompts or trick a user into a tap. SenseCrypt's CIBA push is different. It triggers a face check on the enrolled device, not a tap. So it resists phishing.

How does SenseCrypt resist phishing?

A user enters no password and no shared code at sign-in. A user signs in by face on-device. The sign-in binds to the device.

Related

Retire the password, keep the person

Stand up a passwordless identity provider for your workforce and customers. Free for 30 days, no credit card needed.