The classic scheme for securing a cloud account looked simple for a long time: the user enters a login and password, and for important systems another factor is added - a code from SMS or a lock. There are still a lot of risks to this, but such a model was, in fact, promptly canceled in advance with a secure password.
The problem is that the attacks have changed.
Current phishing has long ceased to be separated by sheets with obvious warnings and requests to “confirm your password”. Attackers copy corporate login pages, copy related logos, domains with similar spellings, QR codes, messages in instant messengers and initiate dialogue under the name of a kernel or technical service.
In such a situation, the headache no longer sounds like the company has two-factor authentication? ”, which means more specifically: how can a koristuvach quickly convey to the evildoer the offense to the factor?
If possible, MFA itself does not pose a problem.
Why is one password obviously not enough?.
Passwords are stripped using the most common authentication method, although their weaknesses have long been known.
People use new or similar passwords in various services, collect transferred combinations, save them in browsers or pass them on to colleagues. When data from one service is lost on Vitik, criminals often check the same login and password on other resources.
Add phishing here - and the problem becomes even more obvious. The customer can enter a complex password of twenty characters, but its cryptographic strength is meaningless if the user himself enters the password on the additional page.
In fact, business has shifted massively to another factor.
Why 2FA is also different.
In practice, two-factor authentication can be used against all different technologies.
The most extensive options:.
SMS code;
one-time code by email;
OTP code for zastosunku;
push confirmation;
hardware key;
biometric authentication.
Formally, from these options, you can add one more factor to the password. However, its resistance to attacks is greatly reduced.
For example, the SMS code is significantly short, and the presence of another factor is limited. Prote yoga can also be vimaniti from koristuvach. Since the login page is fake and asks for a password first, and then a six-digit code, people often enter an insult.
There is no need for one-time codes due to stagnation. The stench is not transmitted by the mobile network, but the user can still manually copy the code from the form created by the scammer.
This principle is a problem: another factor is, however, it is lost in transmission.
Intermediary between customer service and support services.
It’s important to predict attacks in which the phishing site actually acts as an intermediary.
Koristuvach please submit an exact copy of the login form and enter your details. The malicious system transmits them to the helpline service in real time. Since the service asks for a one-time code, there is a detailed page to ask for it as a customer.
As a result, the victim can go through the entire initial login process and still not realize that the password and OTP code were actually stolen by a third-party system.
Therefore, for the protection of critical accounts, another approach is gradually gaining importance: the authentication factor must be technically linked to the help desk, and not simply transmitted to the customer in the input field.
FIDO authentication is based on this very principle.
What does FIDO2 change?.
FIDO2 is a proprietary cryptographic model that replaces the transfer of secrets between the client and the server..
At the time of registration, a pair of cryptographic keys is created for a specific service. The private key is saved on the service side, and the private key is lost on the customer’s device.
When you are asked to confirm your login, the device performs a cryptographic operation. The private key is not transmitted to the server and is not entered manually by the user.
This is a completely different logic for protection.
The phishing site may be almost identical to the original, but the hardware or platform authenticator is responsible for which resource the cloud data was created. Moreover, you can’t simply “ask for the same code” when subdividing a domain, as is not the case via SMS or OTP.
Where is the hardware key?.
FIDO2 can be used with different authenticators. These may be features integrated into a laptop or smartphone, but for the corporate environment, they are especially useful outside of hardware devices.
Such a key is easy to physically view for a specific employee, enable internal access rules, block when spent, and use it independently from a specific employee’s smartphone..
Moreover, the FIDO token should be seen not just as another way to reject the “other factor”, but as a tool for moving towards phishing-proof authentication.
It's a matter of principle. Koristuvach is trying not to learn to easily recognize the cutaneous part of the skin - the task may be unrealistic - but to technically limit the possibility of vikoristata of this type of data on the wrong resource.
De FIDO2 naybіlsh prerechniy.
It is not obligatory to start implementing the program for all devices and all systems.
It’s best to hijack accounts first; compromising them poses the greatest risk..
These can be:.
corporate email;
cloud records of system administrators;
bad infrastructure;
VPN and remote access;
GitHub, GitLab and other development systems;
financial services;
panels for websites;
Kerivniki accounts;
systems that maintain confidentiality and service information.
It is especially important to steal the mail. Having denied access to the corporate screen, the attacker can reset passwords in other services, conduct browsing under the name of a security provider, and carry out significant attacks against their colleagues or partners..
Therefore, the protection of electronic mail is often a good first point for the transition to strong authentication.
This means that SMS and OTP need to be inserted securely.
Not obov’yazkovo.
Cybersecurity professionals rarely have the harsh approach of “throwing everything away.”. Since the company of today's vikorist removes passwords, simple two-factor authentication will improve the situation.
The food is lying at the river riziku.
For the initial internal service, OTP can be very convenient. For a corporate infrastructure administrator or security specialist, access to critical systems may be significantly more.
Therefore, companies should not just check the “MFA approved” box, but separate the cloud records for importance and select the appropriate level of protection.
The human factor is unknown.
The latest technology does not address the need to start developing new technologies.
Employees may understand that they cannot confirm unauthorized login requests, transfer authentication functions to colleagues, or ignore notifications about unknown sessions..
Also, technologies can significantly change the cost of human sacrifice.
People log in, hurry, work on the phone, and may not remember one change to the letter in the domain.. The entire corporate security system will be at risk, so that every one of the hundreds of spies will be able to identify phishing without mercy - the strategy has been risked..
Phishing-resistant authentication changes the model itself: when a person manages to click through to follow detailed instructions, which alone is not enough to deny access.
From “other factor” to stolen digital identity.
The next stage in the development of corporate authentication - without increasing the number of codes that a customer needs to enter.
However, we proceed step by step to the situation, since secrets do not need to be shared.
A change in approach is important for business. Cloud recording protection ceases to be a requirement for password complexity and becomes part of the global architecture of digital identity.
Passwords will be lost for a long time by asking us. SMS and OTP will also not be available anytime soon.
But there, where the price of compromising an account is high, we can still marvel at the upcoming trend - authentication methods that not only add another factor, but also eliminate it from the very mechanism of the phishing attack..
This is where the main advantage of FIDO2 lies: the customer no longer needs to immediately convince him that he has identified a good part. Cryptography takes on part of this robot's work.. Phishing-resistant authentication: why a password and SMS code are not enough to secure corporate accounts read on the HiTech website. Expert.