Passwordless track · 3 min
Pick factors, watch the risk move
Tick sign-in factors and see which attacks still work.
The idea
1A factor is one kind of proof
Something you know, something you have, or something you are. A password plus an SMS code is two factors, but not two equally strong ones.
2Attacks target the weakest link
Phishing pages, SIM swaps and stolen phones each beat different factors. Strength depends on the attack.
3Authenticator codes remove the phone network
An app code works without text messages, so a SIM swap does not help the attacker.
4Passkeys and security keys resist phishing
They sign for the real site only. Prefer them, and keep an authenticator app as a managed fallback.
Try it
Which attacks still work?
Tick the factors a sign-in requires. Ratings are illustrative, from 0 (easy for the attacker) to 3 (hard).
This exercise needs JavaScript. Here is the answer key.
| Guessing or reusing a password | Fake login page | SIM swap | Stolen unlocked phone | |
|---|---|---|---|---|
| Password | 0 | 0 | 0 | 3 |
| SMS code | 2 | 0 | 0 | 0 |
| Authenticator-app code | 2 | 0 | 3 | 1 |
| Passkey (phone or laptop) | 3 | 3 | 3 | 2 |
| Security key | 3 | 3 | 3 | 3 |
Check yourself
1 of 3 Which beats a SIM swap?
2 of 3 Which factor resists a fake login page best?
3 of 3 Two weak factors together are
Answer key
- Which beats a SIM swap? Authenticator-app code. The secret is on the device, not the phone number.
- Which factor resists a fake login page best? Passkey or security key. Signatures are tied to the real site.
- Two weak factors together are Still beaten by the attack both are weak against. Phishing defeats password plus SMS.
Go deeper
Field notes
Runbooks
Passkey rollout playbookRunbookBlueprints
PasswordlessBlueprintLexicon