Balancing security and adoption: preventing account takeover fraud with multi-factor authentication
Blog post from Stytch
Since 2017, the alarming theft of 555 million passwords has led security professionals to consider passwords as inherently compromised, compelling the adoption of multi-factor authentication (MFA) to prevent account takeover fraud. While MFA is crucial for security, the challenge lies in balancing security with user adoption, as illustrated by Coinbase's case study. Despite 95% of Coinbase users opting for SMS passcodes, they account for nearly all successful account takeovers, highlighting the vulnerability of this method compared to more secure options like hardware keys and biometrics. The study finds that although advanced MFA methods such as Time-based One-time Passwords (TOTP), push notifications, and physical security keys offer better protection, their adoption is limited due to complexity and cost. The key takeaway is that engineers need to offer multiple MFA options to encourage user enrollment while educating users about the security benefits of more advanced methods. Stytch advocates for new technologies like passkeys, aiming to combine the usability of SMS with the security of hardware keys to enhance both protection and user experience.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.