Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

MFA – Multi-Factor Authentication

By Sean Lawless on February 23, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

Every morning we sit down at our computers and provide our credentials to the network; user name and password.  Because it has become such a ubiquitous part of modern life, we have a user name and password to everything, we even have password management applications.  This system of challenge and response is designed to prove to the system who you are or authenticate you as a valid user.  As discussed in a previous blog post, who you are and what you do also may determine your permissions within the system if Role Based Access Controls are in place.

Multi-factor authentication (MFA) is a method of more securely verifying the identity of a user of any given system.  The multi-factor comes from requiring more than one piece of identifying information. In the challenge response example above, you know your user name and password.  MFA requires two or more pieces of information from the following categories:

  • Knowledge: something you know (user names, passwords, PIN)
  • Possession: something you have (secure token, bank card, cell phone)
  • Inheritance: something you are (fingerprint, retina, biometric)

A subset of MFA is two-factor authentication (2FA), which is a widely implemented version.  Originally patented in the early 1980s for use with automated teller machines, customers need their bank card, and they need to know the PIN (something they know and something they have).  Two-factor authentication has become extremely common, especially in the Internet and ‘app’ space.  A common method of 2FA is when providers text a code to your mobile phone after a successful challenge and response.  Something you know is your user name and password; something you have is your mobile phone.

Most service providers support 2FA but you may need to request that it be enabled for your account.  You can check if your provider supports 2FA by checking https://twofactorauth.org/.

Photo of Sean Lawless Sean Lawless

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries…

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries, develop and implement practical information security programs based on industry standard frameworks. Sean holds a Bachelor of Science degree from the University of Connecticut and is a member of several cybersecurity professional organizations.

Read more about Sean LawlessEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity, Technology and AI
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo