THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Friday, November 04, 2022
Multi-factor authentication is not an infallible security system. Potential attackers find it harder to commit fraud and steal data. Implementing multi-factor authentication needs to be convenient for users; otherwise, it won't protect their accounts.
FREMONT, CA: A multi-factor authentication (MFA) system reduces legal liability and helps companies comply with data protection regulations. Making MFA work across organizations can involve challenges, and no security measure is foolproof.
MFA needs users to deliver at least two kinds of evidence before they can log in. There are typically three types of authentication factors:
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Passwords or PINs
Authentication key tokens or mobile devices
Facial recognition, fingerprints, or other biometrics
Companies must know and have something to use most MFA systems. A mobile device and the username and password of a user are required to gain unauthorized access to an account protected with MFA.
Low Adoption Rates
One of the initial obstacles an organization may have when deploying MFA is convincing users to utilize it. Sixty-eight percent of individuals do not use MFA whenever it is accessible. Unfortunately, many users view the additional security step as annoying and skip it whenever feasible.
This is particularly true if they must be aware of the additional security it provides. Multiple-factor authentication helps protect firms from attacks that could lead to massive data breaches. For instance, Uber—in 2016, hackers gained unauthorized access to Uber's network and stole the personal information of 57 million people. This was not a sophisticated attack. Rather, an Uber software developer had mistakenly disclosed their login credentials in GitHub-hosted code. Then, anyone with access to their GitHub repository might log into their Uber developer account and have access to important information. Any MFA would have thwarted this attack approach.
The most effective solution is to make MFA as convenient for users as possible by allowing them to authenticate with methods they already use, such as text messages or authentication apps. This implies that the MFA solution does not increase the number of authentication and login methods users must maintain and remember across their many accounts.
Automated Phishing Attempts
It makes it more difficult for phishers to obtain all the information they need by requiring an unauthorized user to have more information or access. It is not difficult for an attacker to intercept authentication signals transmitted to a personal device or spoof a user's device to log in by phishing the necessary information.
This attack is becoming increasingly resistant against the most powerful MFA solutions. Unless companies educate their users on identifying and responding to automated phishing attempts, even a phishing-resistant MFA system will not prevent every assault.
Personal Devices
Personal devices such as smartphones and laptops are frequently utilized in MFA processes, such as sending authentication codes through SMS or email or utilizing an application to produce an authentication key.
These personal gadgets are frequently one of the weakest links in user account security, second only to the users themselves. There are several methods by which malevolent individuals can intercept data destined for a personal device or claim to connect from a device belonging to a genuine user. They can also be easily stolen or remotely manipulated, providing an attacker access to any saved login credentials or unprotected data on the device.
Despite these obstacles, using personal devices in MFA frequently requires compromise. It is the most user-friendly MFA approach. It also increases the number of individuals who opt to utilize the MFA solution. Utilizing personal devices safely at home and work can be mitigated by adhering to recommended practices.
For enhanced protection, businesses can encourage consumers and employees to use hardware-based authentication techniques, such as key generators. According to Google, Google Accounts protected by hardware-based authentication were resistant to the vast majority of automated and mass phishing assaults.
More in News