Phishing-resistant authentication
Authentication whose protocol keeps secrets and valid outputs away from an impostor site without relying on user vigilance, by binding a cryptographic proof to the real verifier or channel.
NIST SP 800-63B-4 section 3.2.5 defines phishing resistance as the ability of the authentication protocol to stop authentication secrets and valid authenticator outputs reaching an impostor verifier, without depending on the claimant’s vigilance. It requires cryptographic authentication and names two methods. Channel binding ties the authenticator output to the protected channel, as in client-authenticated TLS with PIV cards. Verifier name binding ties the output to the verifier’s authenticated identity, such as its domain name, which is how WebAuthn and FIDO2 authenticators achieve it.
The same section says that authenticators involving manual entry, such as a one-time password from an app, token or text message, are not phishing-resistant, because a fake site can pass the code to the real one while valid. Push approvals are also out-of-band, and carry the added risk of MFA fatigue. A password plus a typed code is MFA, yet phishable. At authentication assurance level 2, verifiers must offer a phishing-resistant option, and AAL3 requires one (sections 2.2.2 and 2.3.2).
Exam relevance: a scenario is likely to describe users entering valid MFA codes on a lookalike site, or to ask which authenticator stops credential relay. Candidates are expected to separate multi-factor from phishing-resistant and to prefer a verifier-bound cryptographic option, such as a FIDO2 security key or a passkey, over any code the user types.