Modern Australian
The Times

What is multi-factor authentication, and how should I be using it?

  • Written by Jongkil Jay Jeong, CyberCRC Senior Research Fellow, Centre for Cyber Security Research and Innovation (CSRI), Deakin University
What is multi-factor authentication, and how should I be using it?

Data breaches are becoming commonplace in both small and big tech companies. The most recent victim was Australian telecommunications company Optus, resulting in unauthorised access to the identity data of roughly 10 million people.

Adding to the misery of the victims, this cyber-attack further unleashed a plethora of subsequent phishing and fraud attempts using the data obtained from this breach.

Read more: The 'Optus hacker' claims they've deleted the data. Here's what experts want you to know

Having more rigorous security measures when logging in can help to protect your accounts, and significantly reduces the likelihood of many automated cyber attacks.

Multi-factor authentication (MFA) is a security measure that requires the user to provide two (also known as two-step verification or two-step authentication) or more proofs of identity to gain access to digital services. This typically requires a combination of something the user knows (pin, secret question), something you have (card, token) or something you are (fingerprint or other biometric).

For example, the Australian Tax Office recently tightened some rules for digital service providers on the mandated use of multi-factor authentication. If you use certain services, you’re already familiar with MFA.

But not all MFA solutions are the same, with recent studies demonstrating simple ways to subvert more common methods which are used to lodge cyber-attacks.

Furthermore, people also prefer different MFA options depending on their needs and level of tech savviness.

So what are the options currently available, their pros and cons, and who are they suited for?

There are four main methods of multi-factor authentication

  • SMS: Currently the most common option involving a one-time password (such as a code) sent via text message. Although quite popular and easy to use, the password or code texted to you can commonly be hacked by malicious apps on the phone or by redirecting the SMS to a different phone. The method also fails if your smartphone doesn’t have service or is powered off.

  • Authenticator-based: Another common method, in which an application installed on your smartphone (such as Google Authenticator) generates one-time passwords valid for a very short time span, such as 30 seconds. Although more secure than text messages, malicious apps can still steal these one-time passwords. The method also fails if your smartphone is out of power.

  • Mobile app: Similar to authenticator apps, but a user is sent a verification prompt rather than a one-time password. This requires your smartphone to have an active internet connection and be powered on.

  • Physical security key: The most secure mechanism; it uses a hardware security key (such as YubiKey, VeriMark or Feitian FIDO) that needs to be connected to the device to verify identity – many of these look a lot like USB memory sticks. It’s the current leading method supported by companies like Google, Amazon and Microsoft, as well as government agencies worldwide.

A small usb-key like device with a golden y symbol on it
YubiKey is one example of a physical key you can connect to your device to verify your identity. Formatoriginal/Shutterstock

Each of these four methods varies in usability and security. For example, despite physical security keys offering the greatest level of security, the adoption rate is the lowest, with figures suggesting only a 10% uptake.

Read more: How hackers can use message mirroring apps to see all your SMS texts — and bypass 2FA security

Preference matters

Not only do different multi-factor authentication types vary in security, they also have different levels of popularity. This results in a discrepancy between the most reliable MFA method (the physical security key) and what is actually the most widely used (SMS).

Our team from Deakin University’s Centre for Cyber Security Research and Innovation recently conducted a study on the adoption of MFA technologies. We surveyed more than 400 participants belonging to different age groups, educational backgrounds, and experience with MFA.

Results from our study indicate that people’s preferences are impacted not just by their security needs, but also by usability. The majority of users cared most about the simplicity of the MFA method – this clearly explains why SMS-based solutions still dominate the landscape, even though there are safer alternatives.

In our follow-up study, users were given the most popular physical security keys for one month, to test unsupervised. Preliminary results suggest most users found the physical keys effective and intuitive to use.

However, the lack of platform support and setup instructions created a perception that these keys were difficult and complex to install and use, resulting in a lack of willingness to adopt.

One size does not fit all

We believe there needs to be careful consideration before any government agency or company mandates MFA, with a few key steps to consider.

Different people and organisations will have different needs, so in some cases a combination of methods could work best. For example, an SMS-based solution may be used in conjunction with a physical security key for access to critical infrastructure systems that need higher levels of security.

Additionally, user education and awareness is vital. Many people aren’t aware of the importance of MFA, and don’t know which methods are the safest.

By taking some personal responsibility and using highly effective methods such as physical security keys to protect our most vulnerable accounts, we can all do our part to make the web a safer place.

Read more: What does the Optus data breach mean for you and how can you protect yourself? A step-by-step guide

Authors: Jongkil Jay Jeong, CyberCRC Senior Research Fellow, Centre for Cyber Security Research and Innovation (CSRI), Deakin University

Read more https://theconversation.com/what-is-multi-factor-authentication-and-how-should-i-be-using-it-191591

Vista Cruises Enters "Two-Flagship Era" as Vista Aurora Completes Inaugural Voyage

Vista Aurora Sets Sail along the Yangtze. (Photo courtesy of the company)YICHANG, China — August 5, 2026 — Vista Aurora, a high-end interprovinc...

A Digital Preparation Checklist For International Medical Conferences

An international medical conference compresses many responsibilities into a few days. A delegate may need to present research, move between venues, ...

The Growing Popularity of Lab Grown Diamonds in Sydney and Hong Kong

The diamond industry has changed significantly in recent years as more buyers seek ethical, affordable, and sustainable alternatives to mined diamon...

Modern AI SEO Agency vs Traditional SEO: What’s the Difference

Search engine optimisation has changed dramatically over the past few years. Search engines have become smarter, user behaviour has evolved, and bus...

Caravan Travel for Modern Australian Getaways: Plan a Comfortable Holiday

A family road trip is one of the best ways to explore Australia together. And, travelling by caravan gives you the freedom to take your time, stop a...

Mini Excavator and Trailer Package for Sale: What I Buy as One Deal in 2026

The first client who asked me for a mini excavator and trailer package for sale wasn’t trying to save a few hundred dollars on shipping. They we...

Make Dad a Guest in His Own Home This Father’s Day

Father’s Day can accidentally turn Dad into the unpaid event manager of his own celebration. He lights the barbecue, finds extra chairs, checks wh...

Where to Enjoy Your Off-Road Caravan on the Gold Coast

With a caravan, you can travel anywhere and everywhere without battling the rush of the peak holiday season or last-minute reservations. While the r...

How Osteopathy Supports Recovery from Sciatica and Nerve Pain

Sciatica isn't just annoying. It's genuinely painful. It sits deep in your glute and shoots straight down the back of your leg. It turns something as...

The Winter Jewellery Edit: Five Pieces You'll Wear All Season

As wardrobes shift to cosy knits, tailored coats and rich seasonal textures, jewellery becomes the finishing touch that pulls every winter outfit to...

7 Signs It's Time to Upgrade Your Piston Air Compressor

If you run a workshop, panel shop, or fabrication business anywhere around Perth, you already know what heat and dust do to equipment over a few sum...

How Long Do Bathroom Renovations Melbourne Take? Step-by-Step Process Explained

Planning a bathroom renovation is exciting, but one of the biggest questions homeowners ask is, "How long will it take?" While every project is uniq...

Why Your Skin Breaks Out: The Science of Acne Explained

Acne is the most common skin condition in the world. An estimated 85% of people experience it at some point between the ages of 12 and 24, and a gro...

10 Swimwear Trends Australian Women Are Wearing This Summer

Every Australian summer brings a fresh wave of swimwear trends, but some styles have much greater staying power than others. While fashion constantly ...

Why Regular Skills Updates Are Essential for Licensed Security Officers

A guard at a Brisbane shopping centre gets a call about a shoplifter who's turned aggressive.  They’ve done the job for six years. But their de-...

10 Benefits of Choosing Professional Tutoring Penrith Services

Every student has unique learning strengths, challenges, and academic goals. While classroom teaching provides essential knowledge and structure, so...

Sunshine Coast Baby Classes Prove Big Hit Among First-Time Mums

There's a movement gaining traction on the Sunshine Coast, providing a village of support, socialisation and relief for first-time mothers and babie...

Father's Day Gift Ideas for Men Who Are Hard to Buy For

Some dads are easy to buy for. Others do not want anything, already have everything, or give you the classic "don't worry about me" answer every yea...