SBN

MFA is No Cure for Phishing

EH-Net - Kron - MFA is No Cure for Phishing - YubikeyLast year my Twitter feed became full of stories and retweets about how Google “solved the phishing problem” using hardware multi-factor authentication (MFA) tokens. One such article covering this topic was “Google: Security Keys Neutralized Employee Phishing” by the venerable Brian Krebs. While I have a lot of respect for his work, I have to strongly disagree with the title of his blog post. If you haven’t already read the story, take a moment to familiarize yourself with it. I don’t want to be the one to crush your hopes and dreams, but, frankly, this is untrue.

Before we get too far into this, I want to throw this out there and say that for the sake of this article, I use the term MFA loosely and as a synonym for 2-factor authentication (2FA). I will also mention that I am a fan of MFA and cover some information about MFA in a previous article I wrote for this column, “Credential Phishing – Easy Steps to Stymie Hackers”; however, it is not the cure for everything as some people seem to think. In my years doing sysadmin and information security work for the US Army and in the private sector, I have learned to appreciate the great things that MFA can do to secure systems and communications, something I have even covered in previous articles in this very column. I have also learned that it has its limitations as well. I want to go on record saying this, MFA does not solve the phishing epidemic.

EH-Net - Kron - MFA is No Cure for Phishing - Krebs

There, I said it. Now let me help you understand what is happening here. First and foremost, Google is an advertising juggernaut. Marketing is what they do. This is an important fact when we consider this story. You see, just days (Read more...)

*** This is a Security Bloggers Network syndicated blog from The Ethical Hacker Network authored by Erich Kron. Read the original post at: http://feedproxy.google.com/~r/eh-net/~3/P8ql1QvKv4s/

Avatar photo

Erich Kron

Erich Kron is Security Awareness Advocate for KnowBe4, which hosts the world’s most popular integrated security awareness training and simulated phishing platform with over 70,000 customers and more than 60 million users. A 25-year veteran information security professional with experience in the medical, aerospace, manufacturing and defense fields, he was a security manager for the U.S. Army's 2nd Regional Cyber Center-Western Hemisphere and holds CISSP, CISSP-ISSAP, SACP and other certifications. Erich has worked with information security professionals around the world to provide tools, training and educational opportunities to succeed in information security.

erich-kron has 12 posts and counting.See all posts by erich-kron