Session-Based Phishing and Strong Authentication
Why I avoid the phrase MFA bypass, and why origin-bound authentication changes the session problem.
Identity lesson
I have been careful with the phrase “MFA bypass”. Some phishing attacks relay a legitimate authentication flow and target the resulting session rather than trying to guess a password or reusable code. Authentication may complete exactly as designed while the session is exposed through an untrusted intermediary.
Origin-bound methods such as passkeys provide stronger protection because authentication is tied to the legitimate domain. Help-desk processes and session monitoring still matter because attackers often move towards the weakest recovery or enrolment path.
Engineering consequence
Controlled security testing should be scoped, evidence-driven, and designed around defensive outcomes. Public documentation should explain the risk and mitigations without publishing operational instructions that add no value for defenders.