Multi-factor authentication asks a user to prove their identity in more than one way before gaining access to an account. It adds a layer of defence and raises the difficulty considerably for anyone trying to get in without the right to.
Which raises a fundamental question: why is it not yet mandatory? Email providers in particular would benefit enormously. And online services, rather than asking for yet another username and password, could simply send an access code to a mailbox already protected this way.
It would be a step towards a password-less future, where identity is verified by methods that are both safer and more practical, sharply reducing the risk that comes with holding dozens of accounts.
Imagine being able to verify remotely which email addresses have multi-factor authentication enabled, before a service accepts them. Only accounts at the highest level of security would be admitted.
It is essential, though, that recovery procedures are equally robust. There is no sense in requiring multi-factor authentication if resetting the account then relies on access to another mailbox. We need approaches that guarantee maximum security even when credentials are lost.
Multi-factor authentication is a pillar of personal data protection, and should be seen as the step towards a future in which the absence of passwords is the norm.
Originally published on LinkedIn. Reviewed by the author.