Phishing-resistant second factor
Two physical FIDO keys —one as backup— on the accounts that anchor your digital identity: email, bank, password manager. Someone can talk you into reading out a six-digit app code; they cannot talk you out of a key.
- Level
- Personal
- Cost
- Low cost
- Effort
- Hours
- Evidence
- Observed
What it does not solve
It intervenes in no catastrophic mechanism: a key protects your account, not the system. It also does not cover someone impersonating you to a third party, nor does it help when the fraud arrives by a route that asks for no credentials.
It works if the attack is aimed at getting into an account of yours. CISA ranks the forms of second factor from strongest to weakest and is emphatic: the phishingPhishingA scam by email or message that poses as someone you trust so that you hand over a password or some data, or click where you should not.For exampleThe email that looks like it comes from your bank and urgently asks you to “confirm your details”.-resistant factor is the gold standard, and FIDO/WebAuthn and PKI are the two forms that meet it. Against them, push bombing, SS7 and SIM swapping do not apply [244]Implementing Phishing-Resistant MFAView source ↗.
It does not work if the fraud does not go through your credentials. And watch out for the intermediate rung: the six-digit code from an authenticator app is vulnerable to phishing, because somebody can talk you into reading it out in real time. SMS sits at the bottom of that table, as a last option, and its real risk is not being useless —it is better than nothing— but leaving you with the feeling of having solved the problem.
Evidence. High and from an official primary source, on an observed vectorVectorThe path by which a risk moves from the screen into the world: biological, cyber, military, economic, political, epistemic or loss of control. In this observatory, each vector has its own colour.For exampleA burglar can get in through the door, the window or the roof. The burglar is the risk; the door, the window and the roof are the vectors.: this already happens, it is not projection. The FBI documents impersonation of senior officials with AI-generated voice and recommends turning on the second factor and never disabling it [394]Senior US Officials Impersonated in Malicious Messaging CampaignView source ↗.
Cost. Low, and always two keys: one as a backup, because losing the only one means being locked out of your own digital life.
What it does NOT solve. Nothing catastrophic. A FIDO key intervenes in no scenario on this site; it intervenes in the concrete way AI risk reaches an ordinary person today, which is a different thing and also matters.
Works if…
- AI as normal technology · Works
This is exactly the harm this scenario predicts and the one already materialising for ordinary people today.
- Catastrophe through misuse · Partial
It shrinks your surface against campaigns already using agents, but does nothing to the offensive capability or the attacker's target.
Does not work if…
- Power grab by a small group · Does not work
- Rapid loss of control · Does not work
Risks it addresses
See in the protection matrix →Report a mistake in this entry →
Sources
- [244] Implementing Phishing-Resistant MFA · CISA 2022
- [394] Senior US Officials Impersonated in Malicious Messaging Campaign · FBI IC3 2025