• imouto@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 months ago

    It’s not skipping MFA cos some media can provide more than one factor.

    E.g. YubiKey 5 (presence of the device) + PIN (knowledge of some credentials) = 2 factors

    Or YubiKey Bio (presence of the device) + fingerprint (biological proof of ownership) = 2 factors

    And actually unless you use one password manager database for passwords, another one for OTPs, and never unlock them together on the same machine, it’s not MFA but 1FA. Cos if you have them all at one place, you can only provide one factor (knowledge of the manager password, unless you program an FPGA to simulate a write only store or something).