THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Thursday, July 16, 2020
Many users are applying multi-factor authentication to improve security, but it also has its challenges.
FREMONT, CA: Multi-factor authentication is a security enhancement that allows users to show two pieces of evidence before signing into an account, often referred to as two-factor authentication or 2FA. In general, appropriate credentials fall under one of three categories, something the user knows (a password or PIN), something the user has (a smartphone or physical token), or something they are (their fingerprint) (your fingerprint).
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Credentials must come from two distinct groups for multi-factor authentication. For instance, some apps can send a one-time code to the phone after typing in the username and password. The idea is that while hackers can discover the passwords all too easily today, they almost definitely will not have the phone.
The advantages of multi-factor authentication are advanced security that can be achieved by incorporating additional protection layers. With more layers (factors), it becomes tougher to gain access to accounts, networks, or data for a possible attacker. MFA can also help businesses obtain and sustain compliance, which can decrease future legal liability.
Adoption is generally low.
Passwords are still required in most MFA implementations. Now, the users have to handle the extra layer of protection along with managing the password. Therefore, the users have to juggle authentication styles just like they try to manage passwords because different applications and systems will need different types of MFA.
See Also: Top Cybersecurity Companies
Some users will accept any MFA request.
Criminals often do not even have to engineer others to assist them socially. At SpyCloud, they learned from the Customer Advisory Board members that even though some of the obedient customers are not currently trying to login to something, they will still accept any MFA request. A potent reminder that the most significant security vulnerability remains a human error.
SIM-swapping allows attackers to bypass MFA
A phone's unique identifier is SIM, which stands for subscriber identity module. Mobile phone companies use a small chip-containing card to uniquely identify each of the customers and allow them to connect with their particular mobile networks. Most providers also provide a service known as a SIM swap, which allows converting the mobile account from one SIM card to another. It can be useful if customers have misplaced their phone accidentally or damaged the SIM card in any way.
Cybercriminals have mastered how to utilize this functionality to get access to the accounts of the users. Cybercrime Magazine explains how, in a matter of minutes, Rob Ross, an Apple developer and investor in cryptocurrencies, watched helplessly as one million dollars was drained out of his bank account. More recently, Twitter CEO Jack Dorsey also lost control of his account due to this popular technique.
More in News