Phishing attacks that defeat MFA are easier than ever. So what are we to do?

Why multifactor authentication based on one-time-passwords and push notifications fail.