THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Friday, November 18, 2022
Multi-factor authentication is a staple of many companies' approaches, as few establishments and authorities advocate for or even demand it.
FREMONT, CA: Multi-factor authentication (MFA) requires users to submit at least one authentication factor into a password, or two authentication factors instead of a password, to access a website, application, or network. MFA protects a business from unwanted access better than single-factor (username and password) authentication, as it's harder to hack several authentication factors than a password alone. MFA is a cornerstone of many organizations' identity and access management strategies. Two-factor authentication (2FA) requires a password and a second factor, often a passcode texted to a mobile phone or email, to log in to a system or website.
User knowledge: Passwords, PINs, and security question answers are examples of knowledge factors. Knowledge factors are the most common and most vulnerable authentication factors. Hackers can obtain passwords and other knowledge through phishing, keystroke recorders, spyware, scripts, or bots that generate and test passwords. Other knowledge factors are easy. Hackers who know the user or research social media can crack some security questions. Others are obvious. A common misconception is that requiring a password and security question is MFA. True MFA requires two or more factors, so requiring a second knowledge factor adds some security.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
User possessions: Possession factors include a fob or ID card that opens a physical lock, a mobile device with an authenticator app, or a smart card with authentication information. Many MFA implementations use "phone-as-a-token," where the user's mobile phone receives or generates possession factor information. MFA sends OTPs to a person's phone via text message, email, or phone call. Authenticator apps can generate OTPs, as some authentication systems deliver push alerts consumers can press to verify. Other MFA systems employ hardware security tokens. Some USB tokens broadcast authentication information to the login page, whereas others generate OTPs.
Unique to the user: Biometrics, inherent factors, are user-specific bodily qualities. Fingerprints, voice, face traits, iris, and retinal patterns are innate. Many mobile devices can unlock with fingerprints or facial recognition, and some computers can utilize fingerprints as passwords. Inherent factors are tough. They can't be lost, forgotten, or duplicated. Biometric data can't be updated quickly or easily when compromised, making it hard for victims to cease attacks.
The user's actions: Behavioral variables validate a user's identity based on behavior. Behavioral characteristics include IP address ranges and login locations. Behavioral authentication solutions use AI to analyze users' regular behavioral patterns and highlight anomalous conduct, such as checking in from a new device, phone number, web browser, or location. Adaptive authentication schemes adjust authentication requirements when risk changes, such as when a user logs in from an untrusted device, accesses an application for the first time or accesses sensitive data.
More in News