Introduction
Passwords alone aren't enough. MFA adds a second verification factor—something you have (phone, security key) in addition to something you know (password).
Key Concepts
TOTP: Time-based One-Time Password—apps like Google Authenticator.
U2F/WebAuthn: Hardware security keys like YubiKey.
SMS/Email OTP: One-time codes sent via text or email (less secure).
Real World Context
After enabling MFA, Dropbox reported a dramatic reduction in account compromises. Google found that security keys (U2F/WebAuthn) blocked 100% of automated bot attacks and 100% of targeted phishing attacks, compared to SMS codes which blocked only 76% of targeted attacks.
Deep Dive
Using django-two-factor-auth
python# pip install django-two-factor-auth # settings.py INSTALLED_APPS = [ 'django_otp', 'django_otp.plugins.otp_static', 'django_otp.plugins.otp_totp', 'two_factor', ... ] MIDDLEWARE = [ 'django_otp.middleware.OTPMiddleware', ... ] LOGIN_URL = 'two_factor:login'
Enforcing MFA for Admins
pythonfrom django_otp.decorators import otp_required @otp_required def admin_view(request): # Only accessible after MFA verification pass
WebAuthn Integration
python# pip install django-webauthn # Modern passwordless/MFA with security keys from webauthn import verify_authentication_response
Common Pitfalls
- Offering only SMS-based OTP — SMS is vulnerable to SIM swapping and SS7 attacks; prefer TOTP apps or hardware security keys.
- Not providing backup codes — Users who lose their authenticator device get permanently locked out; always generate and display backup codes during MFA setup.
Best Practices
- Require MFA for privileged users: Admins, finance access.
- Provide backup codes: In case of lost authenticator.
- Prefer TOTP/WebAuthn: Over SMS (SIM swapping attacks).
- Grace period for setup: Let users enable MFA after initial registration.
Summary
MFA significantly improves security. Use django-two-factor-auth for TOTP, prefer hardware keys for highest security, and always provide backup codes for account recovery.