THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Wednesday, December 15, 2021
While usernames and passwords are critical, they are vulnerable to attacks by third parties who use programs to generate random usernames and passwords to hack into a user's device. 2FA adds a layer of security to the accounts by keeping cybercriminals out—and the personal information safe behind closed doors.
FREMONT, CA: For years, the risks of protecting online accounts solely through basic, password-based authentication have been recognized. Nonetheless, progress toward more potent forms of authentication has been slow. As consumers and businesses become more aware of the critical nature of account security, their voices will join those advocating for two- and multi-factor authentication (2FA/MFA).
The National Cyber Security Centre (NCSC) recommends two-factor authentication for 'high value' and email accounts, as email can be used to reset passwords on other accounts. Strong customer authentication (SCA) is regulated in the UK's high-risk finance sector. Meanwhile, Twitter announced that users can now use security keys as their sole two-factor authentication method.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
It's a significant step toward a genuinely password-free future and one that puts additional pressure on other organizations to evaluate their authentication protocols and, where necessary, strengthen security for customers and users.
Importance of 2FA
Strong authentication is required to increase account and online service security. Passwords alone provide insufficient protection because they can be guessed and phished and then used against various accounts in the hope of securing a hit.
Unfortunately, much of this is enabled by behavior. Individuals have a plethora of online accounts. To make it easier to remember all their passwords, they choose simple ones that can be easily guessed in the worst-case scenario. Furthermore, according to our research, they reuse them to the extent that 54 percent of employees use the same password across multiple work accounts. Over a fifth (22 percent) admit writing down passwords to keep track of them. Password reuse enables credential stuffing, which involves the automated entry of log-in information into various digital services. When people reuse their credentials, this type of attack can succeed, exposing various accounts to breaches and takeovers.
Because a password is something that someone knows, it can be shared. Surprisingly, individuals occasionally do this knowingly and willingly, particularly in business settings where colleagues require access to a seldom-used system or application. Apart from intentional sharing, people can also be duped out of their passwords via phishing. Phishing attacks are becoming more sophisticated and, as a result, more difficult to detect. Although an email may appear from a legitimate service provider, such as a bank, it may be directed to a fraudulent website when an unwitting customer clicks on a link. If they enter their information at this point, the cybercriminal can use the phished credentials to gain access to the user's account on the actual service provider's website.
Man-in-the-middle (MiTM) attacks are even more sophisticated and represent another threat to password-only protection. These occur when a cyberattacker infiltrates communications between a service user and a provider, who both believe they are communicating with one another. As with phishing, highly personalized messages and unprotected Wi-Fi networks, and manipulated URLs that appear to be legitimate sites provide a vehicle for MitM attacks.
More in News