Every mainstream MFA method makes the same trade protection now, friction later. Adaptive MFA is the only one that removes the friction without dropping protection.
Green check = protected or supported. Grey dash = not covered.
| MFA Method | Brute force | Key logging | Stolen phone | Phishing | Bucket brigade | Server breach | Laptop theft | Static page auth | Automated 2nd channel | Fast 2nd channel | Logout on leave |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Spriv Adaptive MFA | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Code Scan | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | — | — | — |
| Allow / Deny | ✓ | ✓ | ✓ | — | — | — | ✓ | ✓ | — | — | — |
| TOTP | ✓ | ✓ | ✓ | — | — | — | — | ✓ | — | — | — |
| Hardware Key | ✓ | ✓ | ✓ | — | — | — | — | ✓ | — | — | — |
| SMS | ✓ | ✓ | — | — | — | — | — | ✓ | — | — | — |
Tap a method to see how it works and where it falls short. Only Spriv keeps every promise the row makes.
Adaptive MFA is a risk-based authentication approach that dynamically evaluates the risk associated with each login or transaction. It considers factors such as device, location, user behavior, network, and contextual signals to determine the appropriate level of authentication. Low-risk activity may proceed with minimal friction, while higher-risk activity can trigger additional verification steps or stronger authentication.
On the user's one-click approval via software installed on the mobile phone, Spriv's patented and patent-pending technology creates a unique signature for the user's computer and the phone location. Next time the user logs in from the same computer while the phone is near the same location, Spriv automatically authenticates.
The far majority of automated authentications complete in less than one second. Spriv's combination of automation, speed, low cost, precise data, and indication of whether the user has left their computer creates a new wave of authentication possibilities.
On login, Spriv's server sends a message to the app on the user's phone; the user opens the app and clicks Allow or Deny. Vulnerable to repetition poisoning training users to auto-approve.
Spriv's recommendation: use the Risk Based engine for standard actions (login), and use Allow/Deny only for non-standard actions like address changes or wire transfers.
Six digits shown on the phone by an authenticator app. The user has to type them into the login screen within the time window. Reasonable security but who wants that hassle on every login?
Not in use by Spriv. A USB key with encrypted code. Only one channel of authentication vulnerable by design. Subject to loss, forgetfulness, or being left constantly plugged in when the user walks away. An IT nightmare to manage.
A code sent to the phone by SMS; the user types the code into their computer. Simple, but vulnerable to SIM swap, phishing, and stolen-phone attacks.
Not in use by Spriv. Uses software on the phone to visually scan a code presented on the computer screen. Cannot work with text-only environments like SSH. Requires the user to open the app and hold the phone in front of the screen.
Two free users and two free servers on every plan. No credit card, install in under five minutes.