Seventh Sense
Glossary

SenseCrypt
Technical library

Authentication

Phishing-resistant MFA

Definition
Phishing-resistant multi-factor authentication (MFA) resists attempts to authenticate through an attacker-controlled page.

The test is not how many factors are requested; it is whether a convincing counterfeit site can end the session holding a credential that works.

6 sectionsSeventh Sense / SenseCrypt
On this page

01

What phishing-resistant MFA means

The category covers multi-factor authentication that survives a phishing attempt rather than merely complicating one. The bar is narrow and specific. Assume the person has been fooled completely, assume they are typing into a page the attacker built, then ask what the attacker leaves with. If the answer is a usable credential or a live session, the method failed the test, however many steps it asked for.

Adversary-in-the-middle tooling is what moved this from theory into operations. A modern kit stands between the two parties and forwards each entry upstream the moment it is made, so a second factor the user can read is captured and spent well inside its validity window. Microsoft's Digital Defense Report recorded 146 percent year-over-year growth in adversary-in-the-middle phishing in 2024.

CISA's guidance on phishing-resistant MFA reaches the same place from the defender's side. It separates MFA that raises an attacker's cost from MFA that removes the attack, and recommends the second category for high-value access.

02

Why most deployed MFA is not phishing-resistant

The MFA most organizations run finishes with a human choice: transcribe this number, or accept this notification. Both choices are steerable by a page that looks correct or a caller who sounds senior and rushed.

This is a design property, not a training failure. If the protocol allows a user to move the proof to a stranger, awareness programs can lower the rate but cannot close the gap. The 2023 MGM Resorts incident made the point at the helpdesk rather than the login page: attackers impersonated an employee by phone and were granted access, with roughly 100 million dollars in reported impact.

One-time codes relay in real time

A proxy page harvests the code and redeems it upstream inside its validity window. From the user's side the sign-in eventually succeeds and looks unremarkable, while the attacker walks away with a session.

Tap-to-approve trains the wrong reflex

An approval prompt carries almost no context, so accepting it is cheaper than working out why it appeared. Push bombing is not a clever exploit; it is patience applied to a design that rewards saying yes.

SMS delegates the factor to a carrier

A SIM swap or a ported number moves the second factor to another person without touching the account. The control now depends on a telecom process the organization neither runs nor audits.

Recovery is often the real front door

A strong method frequently falls back to an emailed link or a helpdesk call. Attackers read the recovery documentation too, and they attack the weakest path rather than the advertised one.

03

What makes authentication phishing-resistant

Take away every value a fake site could harvest and the attack has nowhere to go. Qualifying methods share a short list of properties whatever their vendors call them, and that list is worth applying directly to any product under evaluation.

None of these properties depend on the user noticing anything. That is the definition working as intended: the protection has to hold on the day the person is completely convinced.

No reusable secret for the user to disclose

Where the flow contains no password and no readable code, a counterfeit page has nothing to request. Phishing resistance also requires origin binding.

The credential is bound to registered hardware

The proof can only be produced on a device the identity provider already knows. A message captured and replayed from an attacker's machine fails on the first check.

Origin binding, enforced by the browser

A WebAuthn credential is scoped to a site origin, and the browser checks that origin before the authenticator is allowed to sign. A look-alike domain is a different origin, so it receives silence.

Approval happens off the attacked channel

A backchannel flow moves the decision to the user's own device and names the application that asked. The browser under the attacker's control is no longer where trust is decided.

04

Which methods qualify

Standards bodies converge on a short list, and the brevity is the point. Every entry on it deletes the shared secret instead of guarding it more carefully.

A method missing from lists of this kind should be classified as MFA that makes an attack more expensive, not MFA that forecloses it. That can still be the correct choice for low-value access, provided the classification is written down honestly.

  • FIDO2 and WebAuthn passkeys, bound to a relying party origin.
  • Smart cards and PIV credentials, where a certificate on physical hardware is unlocked by a PIN.
  • On-device biometric checks that release a device-bound key rather than a transferable code.
  • Backchannel approval on an enrolled device, where no code is ever displayed to the user.

05

SenseCrypt's phishing-resistance scope

SenseCrypt eliminates the secret instead of defending it. Nothing is typed and nothing is quoted back during a sign-in, which leaves a counterfeit login page with no field worth building and no shared password for a proxy to forward. QR requests are not origin-bound, so that method is not phishing-resistant.

The full phishing-resistant guarantee is a narrower claim, and it belongs to the passkey path. There, SenseCrypt uses real FIDO2/WebAuthn passkeys (ES256) through a roaming authenticator app, and the browser's origin binding is what refuses a look-alike domain. Stating it more widely would be marketing rather than engineering, so it is stated exactly this way: phishing-resistant on the passkey path, via WebAuthn origin binding. Phone sign-in also combines a live face check with a key bound to the enrolled device.

The two factors answer different questions inside the same ceremony. The passkey establishes that the enrolled device took part. The live face check establishes that the enrolled person was there when it did.

Nothing to type, nothing to read aloud

A routine sign-in asks for no value from the person signing in, so the thing an attacker is trying to obtain is never displayed anywhere it could be copied or forwarded.

Capture and comparison stay on registered hardware

Both halves of the ceremony take place on the phone that was enrolled. Nothing running on an attacker's machine can borrow that hardware or the keys it holds.

CIBA push has no approve button

A backchannel prompt starts a face ceremony rather than presenting a yes or no control, which leaves prompt fatigue with nothing to work on. No reflex converts an unexpected notification into an account takeover.

One-time PINs exist only for device binding

The one PIN in the product exists to bind a new device. Delivery is by email, with an SMS copy where the account carries a mobile number, and it plays no part in a routine sign-in. The replacement must also prove a new device key; the account remains bound to the enrolled person through biometric-free, disposable face tokens, and the live face check is still required at sign-in.

06

Frequently asked questions

Is a one-time password phishing-resistant?

No. A user can enter an OTP into a page an attacker controls, and a proxy can spend it against the real site within its validity window. An OTP is a second factor, but it is a relayable one.

Is push-notification MFA phishing-resistant?

Not where approval reduces to a single tap. Attackers either repeat prompts until one is accepted or time a single prompt to look legitimate. SenseCrypt's FAPI-CIBA / CIBA push behaves differently: it opens a face ceremony on the enrolled device instead of offering an approve button, so there is no tap to harvest.

Is the whole SenseCrypt platform phishing-resistant?

The phishing-resistant claim belongs to the passkey path, where FIDO2/WebAuthn origin binding stops a look-alike domain from receiving a valid assertion. Across all methods there is no password and no shared code for a phishing page to collect, which removes the material a credential-phishing kit relays. Phone sign-in also combines a live face check with a key bound to the enrolled device.

Does phishing-resistant MFA stop deepfakes?

It stops the credential theft, not the social engineering around it. The deepfake video call that led an Arup finance employee to authorize about 25 million US dollars, reported in February 2024, never touched a login screen. Phishing resistance protects the sign-in; approval workflows and out-of-band verification protect the transaction.

Where should an organization deploy phishing-resistant MFA first?

Start where a compromised session causes the most damage: administrative consoles, finance approvals, helpdesk tooling and remote access. Those are also the accounts attackers reach for first, which is why CISA's guidance singles out high-value access for the stronger methods.

Next step

The next level of detail depends on your stack, so the fastest route is a conversation.