Two-factor Authentication (2FA)
Two-factor authentication requires exactly two pieces of evidence from different categories before granting access — typically something you know and something you have. It is the most widely deployed security upgrade of the last decade, and the version most people have is the version attackers defeated first. The useful question is no longer how many factors, but whether the factors can be relayed.
| Definition | Exactly two authentication factors, from different categories |
| Relationship to MFA | A subset — MFA means two or more |
| Factor categories | Knowledge, possession, inherence |
| Most common form | Password plus a one-time code by SMS |
| Two passwords | Not 2FA — both are knowledge factors |
| The property that matters | Phishing resistance, not factor count |
| Relayable factors | Anything a person can read and retype, and push approvals |
| Non-relayable factors | Origin-bound cryptographic keys |
What counts as a second factor
The categories exist to ensure the two factors fail differently. A password and a security question are both things you know, and a breach that exposes one frequently exposes the other — so that combination is two steps, not two factors.
| Category | Examples | How it fails |
|---|---|---|
| Knowledge | Password, PIN, security answer | Breached, guessed, phished, reused |
| Possession | Phone, security key, hardware token | Stolen, SIM-swapped, or relayed in real time |
| Inherence | Fingerprint, face | Presentation and injection attacks; cannot be reissued |
Most deployed 2FA is a knowledge factor plus a possession factor, and the possession factor is usually a phone. That choice is what determines the security of the whole arrangement, because a phone number is an unusually movable thing — see phone risk for what a SIM swap does to every signal at once.
Why the count stopped being the interesting number
The original argument for 2FA was sound: a stolen password alone would no longer be enough. Attackers responded by taking both factors in the same interaction.
A real-time proxy sits between the victim and the genuine site, relaying content in both directions. The victim enters a password, which is forwarded. The site issues a challenge, which is passed along. The victim supplies the one-time code, and the proxy uses it inside its validity window. Frequently the attacker then captures the session token, which removes the need to authenticate again at all.
The consequence is specific: any factor a person can read and retype is relayable, and so are push approvals. SMS codes, authenticator app codes and tap-to-approve prompts all fall to the same technique. What survives is authentication cryptographically bound to the genuine site’s origin, because the response the proxy relays is not valid for the domain the attacker is operating.
So “do you have 2FA?” has become a weak question. “Is your second factor phishing-resistant?” is the one that distinguishes a strong deployment from a box-ticking one, and the two questions have entirely different answers in most organizations.
Why this matters for identity verification
2FA protects an account. It says nothing about whose account it is.
An account opened with a stolen or synthetic identity and then secured with strong two-factor authentication is a well-defended fraudulent account. Every subsequent sign-in succeeds correctly, because the fraudster is the legitimate enrollee, and the logs show nothing unusual because nothing unusual is happening.
The second gap is recovery, and it is where attacks concentrate. Every 2FA deployment needs a path for someone who has actually lost their phone — which is exactly what an attacker claims. Where that path falls back on knowledge-based authentication, the whole arrangement reduces to information that breaches have published.
Re-establishing identity at recovery with an authenticated document and a live biometric asks something harvested data cannot answer. That is where identity document verification touches this, and why synthetic and stolen identity controls address what 2FA structurally cannot reach.
What 2FA can’t do
It does not establish who enrolled. It confirms a returning user matches an enrollment, whoever created it.
Most implementations do not resist phishing. Codes and push approvals are relayed by proxies within their validity window.
It does not protect a stolen session. A captured token bypasses authentication entirely, because authentication already happened.
It is only as strong as recovery. The lost-device path is designed to work for someone without their factors, which is the attacker’s exact claim.
Frequently asked questions
What is the difference between 2FA and MFA?
Two-factor authentication uses exactly two factors; multi-factor means two or more, so 2FA is a subset of MFA. Both require the factors to come from different categories — knowledge, possession or inherence. A password plus a security question is two knowledge factors and does not qualify.
Is SMS two-factor authentication safe?
It is substantially better than a password alone and it is the weakest common form. The possession factor can be moved through a SIM swap, and a code the user reads and types can be relayed in real time by a proxy site within its validity window.
What makes a second factor phishing-resistant?
Being cryptographically bound to the genuine site’s origin, so the response is only valid for the real domain and cannot be relayed by a proxy. Anything a person can read and retype — and push approvals too — can be passed through by an attacker sitting in the middle.
Does 2FA prevent fraudulent accounts?
No. It verifies that the person signing in is the person who enrolled. Where the account was opened with a stolen or synthetic identity, 2FA protects that account exactly as designed. Preventing fraudulent accounts requires verifying identity at enrollment.
Related reading
- Multi-factor authentication — the wider category, and the full comparison of methods
- Phone risk — why a phone-based possession factor is movable
- Smishing — the channel most commonly used to harvest one-time codes
- Account takeover fraud — what 2FA defends against, and where attackers go instead