ခဏလေး ဒီလိုပဲ စဉ်းစားကြည့်
2FA (Two-Factor Authentication) က 'you know' (password) + 'you have' (phone, security key) ဒါမှမဟုတ် 'you are' (fingerprint, face) ဆိုတဲ့ factor နှစ်မျိုး ပေါင်းစပ်ထားတာပါ။ Attacker က password steal လုပ်ရင်တောင် ဒုတိယ factor (phone ထဲက code) မရှိရင် login ဝင်လို့ မရပါဘူး။ 2FA method အမျိုးမျိုးရှိပါတယ် — SMS code (အခြေခံ, ဒါပေမယ့် SIM swap attack ခံနိုင်), authenticator app (Google Authenticator, Authy — SMS ထက်လုံခြုံ), hardware security key (YubiKey — အလုံခြုံဆုံး)။
လက်တွေ့ scenario နဲ့ ချိတ်ကြည့်မယ်
Email, banking, social media account တွေမှာ 2FA ဖွင့်ထားတာက data leak ကြီးတစ်ခု ဖြစ်ရင်တောင် account ကို ချက်ချင်းလုံခြုံအောင် ထားပေးပါတယ် — password leak ဖြစ်ရင်တောင် attacker က phone မပါလို့ login မဝင်နိုင်ပါဘူး။ Authenticator app ကို SMS ထက် ဦးစားပေးသင့်ပါတယ် — SIM swap attack (attacker က telecom company ကို လှည့်စားပြီး ကိုယ့် phone number ကို သူ့ device ဆီ ပြောင်းပို့) ခံနိုင်ချေ ရှိလို့ပါ။
အတူတူ ကြည့်မယ်
2FA methods (weak → strong)
----------------------------
SMS code → SIM swap attack ခံနိုင်
Authenticator app → device ပေါ်ရှိ code generate, offline အလုပ်လုပ်
Hardware key → phishing-resistant, အလုံခြုံဆုံး2FA method သုံးမျိုးရဲ့ security level ကို ခွဲခြားနိုင်မည်။၅ မိနစ် စမ်းကြည့်
ကိုယ်သုံးနေတဲ့ email account မှာ 2FA ဖွင့်ထားလား စစ်ကြည့်ပါ။ မဖွင့်ရသေးရင် authenticator app နဲ့ ဖွင့်ကြည့်ပါ (backup code ကို သေချာသိမ်းပါ)။
သတိလေးတစ်ချက်
2FA code ကို phone call/message နဲ့ 'confirm code ပြောပါ' လို့ တောင်းဆိုသူကို ဘယ်တော့မှ မပေးပါနှင့် — real company က ဒီလိုမတောင်းပါဘူး, phishing attempt ဖြစ်နိုင်ပါတယ်။