← all articles

The two factor that actually stops phishing

privacy two-factor phishing security-keys passkeys

Two hardware keys cost me about a hundred dollars. For roughly eighteen months I got the protection of one of them, because I bought the second, put it in a drawer, and never registered it to anything.

I found that out the day I finally sat down to test it. It worked on two accounts. The other six had been set up on evenings when the backup was in a different building and I told myself I would add it later.

That failure has nothing to do with cryptography, and it is more common than any attack in this article. But the cryptography part is where most of the published advice goes wrong, so start there.

Three tiers, and one of them is a different kind of object

Text codes, app codes and hardware keys get written up as good, better, best. As though they sat on one scale and you picked according to budget.

They sit on two. The first pair are the same idea with different delivery: a short number a human reads and types. The third is a different category of thing entirely, and the difference shows up in exactly the place where people lose accounts.

What text codes look like from the carrier side

I run mobile lines on real carrier SIM cards for a living. Singapore networks, physical cards, dozens live at any given time. Numbers get activated, used, cancelled and then recycled, and I watch that cycle every month.

A carrier does not retire a cancelled number. It parks it for a holding period and then reissues it, because the supply is finite and the demand for it never is.

I have taken over recycled numbers and had somebody else’s verification texts land on my hardware inside the first week. Banks, delivery apps, a dating service once. Nobody attacked anything. The previous owner stopped paying, moved on, and never went back through their accounts to change the number.

Then there is the handset. A code that arrives as a text is readable by whoever is holding the phone, and usually by anyone in the room, because the preview sits on the lock screen by default. In practice that means a partner, a teenager, or whichever colleague has the shared work phone on shift. It appears in nobody’s threat model and it is the version that actually happens.

Porting is the one that gets written about. Moving a number to a new SIM is a customer service process, and it has to be, because customers genuinely do lose phones. Anything a helpful human will do for a real customer, they can be walked into doing for a convincing stranger.

None of that makes text codes worthless. If it is all a service supports, keep it, and harden it two ways: turn off lock screen previews, and set a port-out PIN with your carrier. Most carriers support one. Almost nobody enables it.

The app fixes the wire and leaves the person

An authenticator app shares a secret with the site once at setup, then combines that secret with the clock to produce six digits every thirty seconds. Nothing crosses the carrier network. Recycling and porting stop mattering, and so do lock screen previews.

If you change one thing this month, move your codes off text and into an app. It runs about four minutes per account.

It does nothing about phishing.

A six digit code is a thing a person can read out loud. That sentence is the entire weakness, and both of the attacks worth worrying about run straight through it.

The web version: a message says there is a problem with your account, you click, and the page is a copy of the real one served from a domain one character off. You type your password. It asks for your code. You open the app and type six digits. On the other side, a script is relaying both into the real site while you type. Your code is good for another twenty seconds, which is plenty.

The phone version works better. Someone calls, says they are from the fraud team, says there is a suspicious transaction on the account, and needs to verify it is really you. A code is about to arrive. Please read it back. Everything about that conversation is arranged so that reading six digits aloud feels like the cooperative thing to do.

So an app moves you from “a stranger can receive your code” to “you can be talked into handing it over”. Real progress. A long way short of finished.

Why a key cannot be talked into it

A security key is a piece of hardware you plug into USB or tap against a phone. A passkey is the same cryptography with the private half living inside your phone, laptop or password manager. Same mechanism, so treat them as one tier.

When you register one to a site, the key generates a fresh key pair for that site and records which domain it belongs to. The private half never leaves the key. There is no version of it you could speak or paste anywhere.

At sign in, the site sends a challenge. The browser tells the key which domain is on screen. The key signs the challenge together with that domain, having first checked it against what it recorded at registration.

Now put yourself back on the fake page. Same layout, same logo, domain one character off. The key looks at that domain, finds nothing registered against it, and does nothing.

It does not produce a wrong answer. It produces no answer. There is no warning to click through, and no digits to read to the caller, because at no point did any digits exist.

That is the whole argument. The first two tiers ask a tired human to judge a web page correctly at nine in the evening. The third takes the judgement away from the human and gives it to something whose only job is reading domains.

Where a key stops helping

If malware is already running on your machine, a key will not save you. The attacker waits for you to sign in properly and then steals the session, which is the thing that gets used. No second factor of any kind protects a session that is already open.

A key also protects the sign in and nothing beyond it. Account recovery is a separate door with a separate guard, and that is where most people are still wide open. It gets its own section below, because it quietly cancels everything above it.

The order I would do this in

Not every account. That is how people give up on day one.

Email first, and it is not close. Every other account you own has a reset link that lands in it. Whoever controls your email controls the rest by teatime without needing a single other password.

Password manager second, for the same reason.

Then whatever holds money and cannot be reversed. Your bank, if it supports keys, which plenty still do not. An exchange, if you hold crypto, where a withdrawal is final in a way a card charge is not.

Then your domain registrar, if you own domains. I rank that above social accounts because I have watched a registrar account go: mail for every address on the domain gets redirected quietly, while the website carries on looking completely normal.

Five accounts is one afternoon. The rest can live on an authenticator app indefinitely.

Two keys, or a lockout you will pay for

Keys run roughly thirty to sixty US dollars each. Buy two.

A key can be lost, left in a hotel room, or just stop working one morning. If it was the only thing registered on your email account, you are now filing a support ticket with a company that has no phone number and no reason to hurry.

Register both in the same session, while the settings page is already open. That is the mistake I made and it is worth being blunt about it: a backup you never enrolled is a paperweight that makes you feel organised. One key on the keyring. One somewhere physical you can reach and a burglar would not bother with.

Recovery codes are the one place paper wins

Turning any of this on produces a list of one-time recovery codes, usually eight or ten, usually displayed exactly once.

People screenshot them. Those photos then sync into the same account the codes exist to rescue, which is a circle.

Print them, or write them out by hand. Keep the paper where you keep a passport. Paper cannot be phished and it does not sync itself anywhere. If you ever spend one, generate a fresh set, because that list gets shorter without telling you.

The recovery fields are the real back door

You can put the best key in the world on your email account, and if the recovery section still lists a phone number you handed over in 2016, there is a path in that never touches the key.

The reset flow is the flow. Send a code to the number ending in whatever. The account has no way of knowing that number belongs to somebody else now.

While I was cleaning up my own key situation I found a cancelled number sitting in the recovery field of one of my accounts. I sell mobile lines for a living. I know how fast a dead number gets reissued, and I still left one in there, which tells you how much attention that page gets.

So open the security settings on the accounts that matter and read the recovery section like a stranger looking for a way in. Delete any number you no longer pay for. Delete any address you no longer read. Every stale entry is a second front door with a worse lock than the front one.

More tool tests and step-by-step guides are here.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →