multi-factor authentication(opens in new tab) (MFA) is the best thing you can do to prevent malicious users from accessing your account. But what if you lost your security key, deleted your authenticator app, lost all your devices, and can’t prove you’re who you say you are? please don’t Here’s what to do when this bad dream becomes a reality.
What are the three types of multi-factor authentication?
Before we dive in, let’s first review what MFA is and why you should use it.
MFA (sometimes called two-factor authentication or 2FA) is more than just using more to log in. In the world of authentication, he has three ways of identifying himself.
-
something of yours knowlike a password;
-
something of yours that isSuch as fingerprints and other biometric attributes.
-
or something you offallike a hardware security key.
Need to troubleshoot this tricky situation? PCMag’s Max Eddy has a tip. (opens in new tab)
Traditional username and password authentication schemes are just one factor (you know), but multi-factor authentication mixes at least one other factor. That way, even bad guys who know your password can’t access your account because they don’t have the other ingredients they need to access your account.
This is not just theory either. Account Takeover Effectively Eliminated When Google Demanded Hardware Security Keys from Employees(opens in new tab).
The most common way to perform MFA is to receive a one-time use code via SMS.However, SIM jacking(opens in new tab) and other bad guy techniques means this is the least secure way to do MFA.We recommend using an authenticator app instead(opens in new tab) Generate a one-time use code with your smartphone or hardware security key(opens in new tab) Plug in to verify your identity.
Weak MFA is better than no MFA at all, so enable SMS codes if your authenticator app is cryptic and your security key is too high. However, we strongly encourage you to consider alternatives.
What to do if you’re locked out of MFA
A natural concern with MFA systems is the possibility of losing your security key, accidentally wiping your authenticator app, or having your phone stolen and unable to receive SMS codes. Inability to access MFA options may result in being locked out of your account(opens in new tab) eternally.
Luckily, there are a few things you can do if you’re locked out of your MFA-protected account. Please stay logged in on your device, use another MFA option, or contact customer support. All three options are detailed below.
What other MFA options are there?
Many sites and services that support MFA also require multiple to be enabled. For example, Apple requires you to enroll two security keys if you choose to use its MFA option to protect your Apple ID. If you’ve enabled SMS codes, authenticator apps, or security keys in addition to your MFA method of choice, you may be able to use any of those instead.
If another MFA option is available, you will usually see a link such as ‘Authenticate another way’ during login.
Even if you didn’t intentionally enable another MFA method, your site or service may have other options available. For example, the company may be able to send him his one-time SMS code using a phone number on file, or send push notifications to trusted devices.
Where are you still logged in?
If you’re still logged into a site or service on a different device, you may be able to regain access to your account by changing your MFA settings. This may work on your desktop or laptop, but your best bet is to use a mobile device with the service’s app installed. Apps tend to keep you logged in much longer than most websites you visit.
If you find where you are still logged in, look for MFA settings. Once you find them, disable MFA or add new MFA options. do can access. This could be another security key, SMS code, or authenticator app. In most cases, you will need to provide it when changing security settings, so keep your password handy.
While considering this option, be careful not to log out of any service or app until you have full control over it.
Contact Customer Support
If you have exhausted your MFA options and are sure you are not logged in elsewhere, please contact customer support. Some companies may have automated systems to verify your identity and get you back into your account fairly easily.
Other services are more stringent and may require you to provide additional proof of identity such as your driver’s license. In this scenario, it may take days or weeks before you can access your account.
start fresh
However, in some cases, you may not be able to regain control of your account because you do not have the proper documentation or your company’s internal systems are designed to prevent account takeovers. This means that some legitimate users are locked out.
If this is the case, it may be time to start over and create a new account. If you do decide to go this route, contact customer service first.Even if you can’t access your old account, it may be possible to delete it and replace it with a new one. At the very least, the company should be informed so that skilled identity thieves cannot control abandoned accounts later.
How to avoid being locked out with multi-factor authentication
If you’ve already been locked out of your account, your options for regaining control are limited and varied. Maximize your chances of managing your account by taking the time to configure your authentication contingencies.
The easiest option is to enable multiple MFA options if your account supports them. Again, we recommend avoiding SMS codes if possible. If your account has multiple MFA options enabled, you can use alternative methods if your primary method of authentication is unavailable.
Also, activate recovery codes if available. This feature is sometimes called by other names such as: backup code again recovery keyWhatever the name, the idea is the same. A long string of text characters that can unlock an account when all else fails. This should be kept in a safe place as it can be used to take control of your account from you. Consider writing them down in a safe place. If you choose to store your backup codes digitally (e.g. as secure notes in your password manager), make sure they are encrypted and that the service where you store them has MFA enabled for her. please give me.
If you’re using security keys, consider getting a second key and registering it as a backup for the first. Many services allow you to register multiple keys for this very reason. Also, if you use a security key with your Apple ID, Apple requires it. If you decide to upgrade to a new security key, keep your old security key as a ready-made backup.
Some authenticator apps back up the code generation data so you can easily migrate from device to device without the hassle of re-registering the authenticator app for each site or service. Some go even further by storing code generation data in the cloud, allowing you to generate code on multiple devices simultaneously. We consider backups to be fine, but being able to generate code on multiple devices at the same time poses a security risk.
Don’t be afraid of multi-factor authentication
Turning on MFA feels like a huge commitment and a little scary.After all, if you can keep the bad guys out, you might be able to keep them you out too. However, using MFA ensures that your account is secure and the risk of being permanently locked out is minimal for most accounts. With a little preparation, you can prevent it from happening at all. No need to wait. Enable MFA whenever possible.
Note that MFA is only part of the equation.up to the passkey(opens in new tab) Or when passwordless authentication becomes mainstream, unique complex passwords should be used(opens in new tab) for all sites and services.password manager(opens in new tab) Use passwords along with your MFA system of choice, as humans are far better at inventing and remembering passwords.
Finally, even the best authentication systems fail when malicious individuals have unfettered access to your computer or mobile device.We highly recommend using local antivirus software(opens in new tab) Prevent attackers from gaining footholds on your machine.
This article originally appeared on PCMag.com.(opens in new tab), Mashable’s sibling site. PCMag.com(opens in new tab) A technology authority, providing lab-based independent reviews of the latest products and services.