Cybersecurity Awareness Month Week 2: Turn on multi-factor authentication

Long, unique passwords are an important first step toward keeping your data and systems secure. MFA adds an extra layer of protection that keeps your accounts safe if your password is stolen or compromised. We require multi-factor authentication (MFA) at the college, but you should enable it wherever possible. This can be the difference between a harmless phishing attempt and a full account compromise.
What is MFA?
MFA is a security process that requires users to provide two or more verification factors to gain access to an account or system. The first factor is usually “something you know” like a password, PIN or pattern. The other factors fall into a couple other categories:
The first is “something you have”— This means that the second factor is tied to a physical object you own or have access to. In most cases, this is tied to a user’s phone, but could be a physical smart card or key as well.
The other is “something you are” – This uses a record of some unique, biological characteristic to confirm that you are…well… you. Though not impossible, it would be very difficult for a hacker to copy something like your fingerprint.
Common MFA Methods
There are several ways MFA can be implemented, and understanding the most common methods will help you recognize and choose the best from the available options.
- Text Message (SMS): A unique code sent to your phone.
- Phone Call: A code provided audibly via call to a mobile or landline phone.
- Time-Based One-Time Password (TOTP): Codes generated by an app like Google Authenticator, Microsoft Authenticator, or Duo.
- Biometric Verification: Fingerprint scans, facial recognition, or other biometric checks.
- Hardware Token: A dedicated device, like a YubiKey or key fob, that generates unique access codes.
Note: Due to the prevalence of SIM cloning and number porting attacks, an increasing number of professionals advise against relying on a text or call-based MFA method if other options are available.
Where Should You Enable MFA?
You should enable MFA everywhere possible, but it’s especially critical for your most important accounts. Start with your bank and other financial accounts, where the stakes are highest. Your email accounts are equally important, since they often contain sensitive information and can be used to reset passwords or MFA settings on your other accounts. (A compromise here could open the door to everything else you use.) Social media accounts should not be overlooked either, as attackers can exploit them to impersonate you, spread scams, or harvest information about you, your family, friends, and colleagues. Essentially, if it’s used in a significant social or financial part of your digital life, you should lock it down using the most secure methods available.
Can MFA be hacked?
While MFA significantly strengthens your defenses against cybercriminals, it is not entirely foolproof. Security professionals nowadays advise against using phone-based MFA, such as text messages or voice calls, because SIM cloning and number porting attacks have become easier for hackers to pull off.
Even with MFA, phishing is still a very serious issue. No amount of security checks will keep accounts safe if the user absentmindedly puts their credentials and MFA code into a fake login page. Always make sure you’re checking links and only logging into trusted domains. For example, if your browser or password manager normally auto-fills your login information to Gmail but suddenly does not, take that as a warning sign that the page you’ve found yourself looking at is probably phony.
Go deeper on this topic by checking out the resources found here. https://www.staysafeonline.org/articles/multi-factor-authentication
Remember…
About phishing simulations.
We’ll conduct two phishing simulations for students in October and November. Phishing simulations for employees will continue at the monthly cadence we started in the spring. As always, if you see unusual or suspicious emails, report them as you would any other spam or phishing messages. Your vigilance keeps our community safer.
Get your cybersecurity training done.
We aim for all faculty, staff, and first-year students to complete Cybersecurity 101 by the end of the month. It doesn’t take long! Employees who complete the training by the end of October will be entered into a drawing for a $20 Bon Appétit gift card. Separate courses for students and employees can be found in Moodle.
Our online Cybersecurity Town Hall is on October 26.

Join Kendall George, information security officer for Carleton and St. Olaf Colleges, at our annual Cybersecurity Town Hall: Cybermaxxing to Securitymog the Ops. This engaging, interactive session will describe the current state of cyberthreats in higher education and the steps you can take to keep both campus and your own digital life secure. There will be ample time for questions and answers.
Stay safe out there.
Kendall George
Information Security Officer
Carleton and St. Olaf Colleges