Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Passwordless track · 3 min

Pick factors, watch the risk move

Tick sign-in factors and see which attacks still work.

The idea

  1. 1A factor is one kind of proof

    Something you know, something you have, or something you are. A password plus an SMS code is two factors, but not two equally strong ones.

  2. 2Attacks target the weakest link

    Phishing pages, SIM swaps and stolen phones each beat different factors. Strength depends on the attack.

  3. 3Authenticator codes remove the phone network

    An app code works without text messages, so a SIM swap does not help the attacker.

  4. 4Passkeys and security keys resist phishing

    They sign for the real site only. Prefer them, and keep an authenticator app as a managed fallback.

Try it

Which attacks still work?

Tick the factors a sign-in requires. Ratings are illustrative, from 0 (easy for the attacker) to 3 (hard).

This exercise needs JavaScript. Here is the answer key.

Guessing or reusing a passwordFake login pageSIM swapStolen unlocked phone
Password0003
SMS code2000
Authenticator-app code2031
Passkey (phone or laptop)3332
Security key3333

Check yourself

1 of 3 Which beats a SIM swap?

2 of 3 Which factor resists a fake login page best?

3 of 3 Two weak factors together are

Answer key
  1. Which beats a SIM swap? Authenticator-app code. The secret is on the device, not the phone number.
  2. Which factor resists a fake login page best? Passkey or security key. Signatures are tied to the real site.
  3. Two weak factors together are Still beaten by the attack both are weak against. Phishing defeats password plus SMS.