The Royal Armoury · Notice the Third
Free MFA Poster: The Second Factor
The thief has your password, subject. He did not work for it and he did not break anything to get it. He bought it, the way you would buy a fish. What stops him is the second thing your door asks for, and it costs you a minute to arrange.
Take up arms
Printable at A4 and US Letter, free, for a workplace noticeboard or a classroom wall. If you are running MFA awareness training, or an awareness campaign that has to cover the second factor in one sheet, this is the sheet.
| Issue | Format | Weight |
|---|---|---|
|
|
PNG, 300dpi | 5.4 MB |
|
|
PNG, 300dpi | 5.2 MB |
|
|
PNG, 300dpi | 907 KB |
|
|
PNG, 300dpi | 795 KB |
|
|
JPG, 1600px | 473 KB |
|
|
PowerPoint | 1.9 MB |
|
|
PNG, 16:9 | 1.9 MB |
The black and white issue is for the printer down the corridor, the one with only the black cartridge left in it. Same thief, same door, no gilding.
The PowerPoint slide arrives with speaker notes from the court: what each row means in plain terms, what to say to the person who insists it will slow them down, and why the logs would never have caught this. Drop it into any awareness deck; the King asks only his name on the door.
What counts as a second factor, for the record
Multi-factor authentication, two-factor authentication, MFA, 2FA. Four names, one idea, and the heralds are aware of the problem. This court calls it the second factor, and so does the poster.
- A password on its own is not one. Credentials are stolen in bulk and sold on, so the safe assumption is that yours is already out there somewhere. The second factor exists for exactly that day.
- A code sent by message: better than nothing. Text messages can be intercepted, by SIM swap and by attacks on the phone network, which is why the standards bodies rank it last of the working options. It is still far better than no second factor at all. Nobody should switch it off on account of this poster.
- A code from an app: good. It is generated on your device from a shared secret and a clock, so it works with no signal: on a train, in a lift, abroad. It can still be typed into a convincing fake site, which is why it is not the top row.
- Your face or your fingerprint: good, and faster. Device biometrics, which in practice usually unlock a passkey stored on the device. Quicker than typing anything, which is the honest reason people keep it switched on.
- A key you tap or plug in: best. A security key is bound to the real site's address, so a lookalike page cannot use it even if you are completely taken in. It is the only option on the sheet that resists phishing rather than merely surviving it.
Turn it on for email before anything else, then banking, then anything holding payment details. Email first, because it is the account that resets all the others.
One thing the poster says quietly and the court will say plainly: a correct password used by the wrong person does not look like an attack in any record you keep. Nothing is forced, nothing is broken, and the door opens politely. The second factor is what stops it; the log only writes it down afterwards.
The full proceedings are on record: Do I really need two-factor authentication?, in which the court makes its own gate impossible and a thief walks into fifty households without touching one.
Putting an October campaign together? This poster and everything else worth using is gathered on the Cybersecurity Awareness Month page.
The terms of issue
Free to use unaltered: at work, in a classroom, in a newsletter, on any noticeboard that will have them. Not for resale. The credit is already printed on the thing, so there is nothing for you to add.
That is the whole treaty. The crown's lawyers are disappointed by its brevity and have been informed that the matter is closed.
Requests, questions and corrections reach the court at [email protected].
More arms are being forged. The smiths have finished arguing about the second factor and have moved on to the backups.