/* ---- Google Analytics Code Below */
Showing posts with label MFA. Show all posts
Showing posts with label MFA. Show all posts

Monday, October 25, 2021

MFA is Phishable

Multi factor authentication (MFA) is seen as a strong means of security, but can be less so, here some reasons why.

Why Is the Majority of Our MFA So Phishable?

Published on October 20, 2021

By Roger Grimes in Linkedin,   Data-Driven Defense Evangelist at KnowBe4

The huge push to multifactor authentication (MFA) is ostensibly to help people avoid getting so easily phished. But are we making the same mistake with MFA and making too much of it too easily phishable? Will we be pushing our organizations and end-users to MFA only to repeat many of the same mistakes? The US government is worried about it. You should be worried as well.

The U.S. government has been pushing people to avoid SMS- and voice call-based multifactor authentication (MFA) for years, but their most recent warning is to avoid any MFA that is overly susceptible to phishing. That is only commonsense (since most data breaches involve social engineering), but what MFA types do they mean and what does that mean for you? Read on.   ... '

Wednesday, December 16, 2020

Unrolling the SolarWinds Attack and Implications

 The recent SolarWinds hack, started this March,  and was apparently much more serious than expected, including many government and defense applications.  I will pass along the most interesting aspects of this, and aim to link to longer term implications.

I note in Schneier's blog a piece on how the Solarwinds hack bypassed multi factor authentication.  Instructive.

Then in "Security Now' with Steve Gibson an overview of the whole event as understood to date:

https://www.grc.com/sn/SN-797-Notes.pdf  Pages 12-17,   with attached podcast which outlines the extent and severity of the hack.   Below the intro.  Much more at the link:

SolarWinds

FireEye:

The story begins with last Tuesday's news and admission from FireEye that they were hacked. FireEye is a three and a half billion dollar security company, one of the largest of its kind in the world. It was founded in 2004, has more than 8,500 customers spread across 103 countries and more than 3,200 employees worldwide.

https://www.fireeye.com/blog/products-and-services/2020/12/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html

In his disclosure of the event, FireEye's CEO Kevin Mandia explained what they knew then: ... "

Friday, November 13, 2020

Microsoft Warns about Dangers of MFA on Phones

 This was mentioned in a recent conversation about mlti factor authentication (MFA).  Especially using your phone as a means of MFA.   Good warning.  Includes links to other posts about the topic.

Microsoft Is Warning Against Using This Common Way of Protecting Your Most Important Accounts Those six-digit text message codes aren't as secure as you think.

By Jason Aten  TECH COLUMNIST  In Inc

Microsoft Is Warning Against Using This Common Way of Protecting Your Most Important Accounts

If you're using your phone for multi-factor authentication (MFA) to keep your important accounts safe, Microsoft has a warning for you. We'll get to that in just a second, but first, let's be clear on what we're talking about. MFA is an additional level of security beyond just a user name and password. For example, it's when your bank sends you a text message with a six-digit number that you have to enter on the website in order to get access to your accounts. 

The idea is that if someone were to get access to your user name and password--either through some kind of data breach, or simply because they were able to crack it--your account would still be safe since presumably only you would have access to the code sent to your phone. The problem is, that's not necessarily true. 

That's why Microsoft is warning people that while using text messages or phone verification as a form of MFA is better than nothing, it isn't as secure as you might think. That's because your phone number can be hacked, spoofed, swapped, or stolen. 

Specifically, Alex Weinert, Microsoft's director of identity and security wrote a blog post encouraging people to stop using their phone number for MFA. Weinert points out several reasons, including that SMS messages are not encrypted and that hackers have gotten very good at SIM-swapping.    .... "