Sentry Labs Advisories← Advisories
SL-2025-013 High Access Control

Multi-factor authentication that actually holds

PUBLISHED 14 NOV 20256 MIN READ
Advisory Record SL-2025-013·r3
Severity
High
Status
Reviewed
Affected area
Access Control
Published
Last reviewed

Turning on multi-factor authentication is one of the highest-value security actions available, and also one of the most misunderstood. "I have 2FA" is not a single statement, the gap between a texted code and a hardware security key is the difference between an inconvenience for an attacker and a wall they cannot climb. For an account that can move money, the type of second factor is not a detail; it is the control.

§01The problem with codes

A one-time code, whether from an SMS or an authenticator app, shares a fatal property: the user can be tricked into typing it somewhere. A convincing phishing page simply asks for the code and relays it to the real site in real time. The user’s second factor works perfectly, for the attacker. SMS carries an additional weakness, the SIM swap, in which the attacker persuades a carrier to move the number to their own device. Codes raise the bar, but they do not change the game.

§02What phishing-resistant means

Hardware-backed authentication, security keys and the passkey standards built on the same cryptography, closes the relay. The key signs a challenge that is cryptographically bound to the exact domain requesting it, and it never releases a secret the user could hand over. A lookalike site gets a signature that is worthless anywhere else. There is nothing for the user to read out, retype, or be tricked into disclosing, because the browser and the key negotiate the proof directly.

§03Cover the whole surface

Strong authentication on the login page is undermined if the recovery flow is weak. Attackers routinely bypass a hardware key by attacking the "lost access" path, a security question, a support call, a fallback code. Enrol more than one key, remove weaker fallbacks where the platform allows, and treat account recovery with the same seriousness as login. The same discipline extends to machine access: a service that trades on your behalf should hold a scoped, tightly bound credential, not a human’s password.

§04The upgrade worth making

If there is one change that most reduces the odds of a stolen account, it is moving the accounts that matter from codes to phishing-resistant keys. It is a quiet, unglamorous upgrade that removes an entire category of attack. This advisory is educational and illustrative and is not security advice for any specific deployment.

Institutional execution, engineered.

Institutional-grade algorithmic and high-frequency trading infrastructure.

Request access →

Educational content only. Algorithmic and high-frequency trading carries substantial risk of loss. All figures are illustrative / simulated, are not indicative of future results, and nothing here is financial, security, or risk-management advice.