Comparing Multi-Factor Authentication Methods from SMS and TOTP to FIDO2/WebAuthn and Passkeys: A Qualitative Study of Practitioner Perspectives
The escalation of cyber-attacks has intensified the need for stronger multi-factor authentication (MFA), motivating a shift from traditional knowledge- and possession-based factors, such as SMS one-time passwords (OTP) and time-based one-time passwords (TOTP), toward FIDO2/WebAuthn credentials and passkeys. This study...