Skip to content

Comment on Internal Twitter Credentials Used in DNS Hack, Redirectparent

Comments

That's not multi-factor authentication.

True multi-factor authentication involves a combination of something you know (eg, your password), something you have (your phone, a fob, etc.) and something you are (generally biometric things, which for obvious reasons haven't picked up too much).

Multiple security questions are just additional things-you-know, and as such, aren't multifactor.

Ah, thanks, you're right.

My bank's website specifically calls it "multi-factor authentication", and I never bothered to double-check the term.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.