← build journal
Entry 131 February 2026

Session-Based Phishing and Strong Authentication

Why I avoid the phrase MFA bypass, and why origin-bound authentication changes the session problem.

Identity SecurityPhishingDetection Engineering

Identity lesson

I have been careful with the phrase “MFA bypass”. Some phishing attacks relay a legitimate authentication flow and target the resulting session rather than trying to guess a password or reusable code. Authentication may complete exactly as designed while the session is exposed through an untrusted intermediary.

Origin-bound methods such as passkeys provide stronger protection because authentication is tied to the legitimate domain. Help-desk processes and session monitoring still matter because attackers often move towards the weakest recovery or enrolment path.

Engineering consequence

Controlled security testing should be scoped, evidence-driven, and designed around defensive outcomes. Public documentation should explain the risk and mitigations without publishing operational instructions that add no value for defenders.