En esta noticia

The Cybersecurity and Infrastructure Security Agency (CISA) belongs to the Department of Homeland Security (DHS) of the United States. It is responsible for reducing cyber and physical risks.

On its official website, CISA offers cybersecurity advice to avoid falling victim to fraud and identity theft, as well as information about programs, measures, and advances. One of the most recommended is the use of Multi-Factor Authentication (MFA).

What is and how does the Multi-Factor Authentication recommended by CISA work?

It is a barrier that provides additional security by confirming identity when logging into personal accounts through confirmation using a second factor, such as entering a code sent by SMS or generated in an authentication app such as:

  • Google Authenticator.
  • Microsoft Authenticator.
  • Proton Authenticator.
  • Twilio Authy.
  • 2FAS.

This means that even if a cybercriminal gets your password, they will not be able to complete the second step to access your accounts.

What is it for and why is it important?

Activating MFA for accounts and applications that offer the option enables protection with an extra layer of security:

  • Banking information.
  • Online shopping.
  • Social networks.
  • Email.
  • Companies.
  • Your identity.

It is important because it allows an additional layer of security to be added to existing barriers such as passwords.

How to activate Multi-Factor Authentication to protect accounts and applications?

To protect accounts and applications with MFA, the following steps must be followed, according to CISA:

  • 1- Go to settings in the account profile, it may be found as:
    • Configuración de la cuenta.
    • Perfil.
    • Preferencias.
    • Privacidad.
  • 2- Select Security settings, it may appear as:
    • Seguridad.
    • Contraseña y seguridad.
    • Similar.
  • 3- Find and activate multi-factor authentication, which may be found as:
    • Autenticación de dos factores.
    • Autenticación en dos pasos.
    • Similar.
  • 4- Confirm your choice of method among the options offered by each platform:
    • Recibir un código numérico por mensaje de texto u correo electrónico.
    • Usar una aplicación de autenticación, que generan un código nuevo cada 30 segundos.
    • Biometría.

Another security measure to complement Multi-Factor Authentication

The use of simple passwords such as number sequences or common identifying information, such as birth dates and pet names, is not secure for protecting important accounts personal information.

However, CISA recognizes that it may be “impossible” to create a password that is different for every account, unique, and secure. For this reason, it recommends using a password manager to complement multi-factor authentication.

The recommendations are:

  • That they be long.
  • That they be random.
  • That they be unique.