Introduction: The Paradox of the Double Key
We have all experienced this moment: after entering our password on a site, a window appears asking for a code sent via SMS or validation through an app. Multi-factor authentication (MFA), or two-factor authentication (2FA), has become the absolute standard of modern cybersecurity. It is based on a simple principle: even if a hacker steals your password, they cannot access your account without the second factor (your phone, a fingerprint, or a physical key).
However, this mechanism raises a troubling paradox. To protect us from data theft, we are asked to link our digital identities to extremely precise physical and personal elements. In other words, to secure access, we must often provide irrefutable proof of our real identity.

The CNIL, in its recommendations on multi-factor authentication, emphasizes the need to strengthen the protection of personal data in the face of increasing cyberattacks. But as hackers become more sophisticated, the line between "security" and "surveillance" thins. While MFA is an effective shield against intrusion, is it not also a permanent tracking tool that makes digital anonymity nearly impossible?


