<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>MFA on Security Blueprints</title>
    <link>https://securityblueprints.io/invariant_tags/mfa/</link>
    <description>Recent content in MFA on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:45 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/invariant_tags/mfa/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Mandatory Hardware Second Factor</title>
      <link>https://securityblueprints.io/security-invariants/hardware-second-factor/</link>
      <pubDate>Mon, 28 Oct 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/security-invariants/hardware-second-factor/</guid>
      <description>Overview A mandatory hardware second factor requires all user authentication to be completed using a physical security key, in addition to traditional passwords. This approach effectively nullifies password phishing and credential stuffing attacks.&#xA;Benefits Password Phishing Protection: Password compromise alone becomes insufficient for account access Elimination of Replay Attacks: Unlike SMS or time-based tokens, hardware keys cannot be intercepted or replayed Real-World Implementation Major technology companies have proven the effectiveness of this security invariant through comprehensive deployments:</description>
    </item>
  </channel>
</rss>
