|
Not all MFA's are created equal Despite the growing tide and sophistication of cyber attacks, organisations continue to rely on legacy authentication methods such as usernames and passwords and mobile-based authenticators to secure access to critical and sensitive applications and data. A recent Google Cloud report indicates that 50% of compromises of enterprise cloud environments in Q4 2022 could be attributed to weak passwords. Organisations face mounting pressure from regulators and cyber insurers to strengthen cybersecurity defenses with multi-factor authentication (MFA), adding one or more additional pieces of evidence to the authentication process. However, while any form of MFA will offer better security than password-based authentication alone, the truth is not all MFA is created equal . Legacy mobile-based MFA such as SMS, one-time passcodes (OTP) and push notification apps are highly susceptible to account takeovers from phishing, social engineering and man-in-the-middle (MiTM) attacks. Yet, up to 53% of organisations choose mobile-based authentication as their MFA form factor. Why is that? Because most organisations remain unaware of the security risks with mobile authentication. Today a data breach costs an average of $9.44M in the US and $4.35M globally but cyber attacks can also erode trust, disable critical infrastructure, disrupt core operations, increase cyber insurance premiums and result in the loss of intellectual property. Successful cyber attacks are the reason why regulators now specifically mandate phishing-resistant MFA as defined in NIS2 for the EU and the global PCI DSS v4.0 standard and yet across the industry, confusion still exists about what forms of MFA are truly secure or phishing-resistant. The dark truth is that no form of mobile authentication is phishing-resistant. Further, your MFA strategy RoI can vary widely in terms of cost, user experience, coverage and even the ability to bridge to a passwordless future, depending on what MFA approach you choose. In this whitepaper, we'll reveal the top five mobile authentication misconceptions to help you re-evaluate your long-term MFA strategy and to consider the shift to modern MFA. In fact, we'll demonstrate that legacy mobile-based MFA is broken , and how you can achieve modern, phishing-resistant MFA. |
|||||||||||||
|
Common forms of mobile authentication The most common forms of mobile authentication rely on the human element - the manual entry of an output (code) or the approval of a sign-in request. The human element of authentication can have a direct impact on security risk, user productivity and support costs if the solution doesn't offer an optimal user experience. In fact, 82% of data breaches can be tied to the human element - social attacks, credential theft, misuse or errors. |
|||||||||||||
![]() |
|||||||||||||
|
Five common misconceptions related to mobile authentication
Below are the top
five mobile authentication misconceptions that put organisations at risk
of account takeovers and increased OpEx and CapEx costs, if not
addressed:
|
|||||||||||||
|
Misconception #1:
Reality: Every form of mobile authentication can be hacked Security is the top driver for MFA deployments, but while some forms of mobile authentication are more secure than others, no form of mobile authentication is phishing-resistant. Phishing-resistant MFA processes rely on cryptographic verification between devices or between the device and a domain, making them immune to attempts to compromise or subvert the authentication process (e.g. phishing, brute force attacks). According to the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63, currently only two forms of authentication meet the mark for phishing-resistant MFA: PIV/smart card and FIDO2/WebAuthn. |
"Any form of MFA is better
than just a username and password, but most MFA can still be phished. It didn't
take long to realise we needed stronger authentication for all employees that could not be phished." Daniel Jacobson Senior Director of IT, Datadog |
||||||||||||
![]() |
|||||||||||||
|
Today's cyber threats are increasingly targeting legacy MFA including passwords and
mobile authenticators that are vulnerable to modern cyber threats. In 2022, a social
engineering attack on messaging service Twilio led to the compromise of the Twilio
platform and its customers, undermining the security of the OTP services provided
during that time
. In 2022 and 2023, phishing attacks and stolen credentials were used
to access sensitive systems (e.g. Uber
) or data (e.g. American Airlines
) or via third
party credentials (e.g. AT&T
, Chick-fil-A
).
When authentication is based upon knowledge or people, this is a recipe for risk.
People make mistakes-they can be fooled to approve authorisation requests, supply
OTP codes or install software. No amount of security training can eliminate the risks of
modern phishing attacks against mobile authentication-the mobile device itself raises
several red flags:
|
MFA is critical, but not all MFA methods are created equal. Twitter used application-based MFA, which sent a request for authentication to an employee's smart phone. This is a common form of MFA, but it can be circumvented. During the Twitter Hack, the Hackers got past MFA by convincing the Twitter employees to authenticate the application-based MFA during the login. The most secure form of MFA is a physical security key, or hardware MFA, involving a USB key that is plugged into a computer to authenticate users. This type of hardware MFA would have stopped the Hackers, and Twitter is now implementing it in place of application-based MFA.
New York Depart of Financial
Services |
||||||||||||
|
In 2020, a small group of teenagers targeted Twitter employees with a spear phishing attack to obtain access to employee credentials and authenticator app codes, then accessed the internal network to seize high-profile cryptocurrency accounts and scam the public of over $118,000 in bitcoin . In another instance, a ethical hacker demonstrated that just $16 and a few seconds was all it took to completely and invisibly take over social media accounts that had been protected by OTP-based MFA . A Google, NYU, and UCSD analysis of 350,000 real-world hijacking attempts revealed that a SMS-based OTP blocked 76% of targeted attacks and a mobile push app blocked 90% of targeted attacks . In other words, mobile authentication experiences a 10-24% attack penetration rate . In fact, the risk of SMS interception is so high that NIST called for SMS to be deprecated as a method of authentication . If this is news to you, you're not alone . Only 22% of respondents to an industry surveyed are aware that security could be a problem with SMS-based authentication . While OTP authenticators are the least secure form of mobile authentication, they remain the top deployed authenticator across 58% of organisations . |
|||||||||||||
|
Every mobile authenticator can be hacked
Account takeovers occur when a hacker successfully gains access to a user's credentials via:
|
|||||||||||||
How fake login page defeats legacy MFA![]() |
|||||||||||||
|
Misconception #2:
Reality: It's more expensive than you think
Mobile authentication is perceived to be relatively inexpensive to roll out, leaving many organisations satisfied they have found a cost-effective solution for authentication. However, mobile authentication carries with it many hidden costs.
If you require employees to use mobile authentication, regulation may state that you cannot require employees to bear the mobile costs
, also GDPR regulations may prevent company access data being held on a personal device. As a result, you
must
factor in the total cost of device ownership
: hardware, recurring service costs, device management solutions, security solutions and even replacement costs to keep up with the demand for new devices. Even in BYOD situations, governance and support costs remain high for legacy authentication. Forrester found that large organisations spend up to $1 million each year in staffing and infrastructure to handle password resets from employees-and passwords only represent the first factor in 2FA or MFA authentication . An estimated 10% of devices are lost, stolen or broken each year in organisations, another factor increasing the cost for mobile authentication (not to mention risk) . While security teams expend costly effort setting and managing password policies at scale, any time a user struggles with legacy authentication, they are not being productive . This includes forgotten passwords, account lockouts, password reset policies, time consuming workflows to generate and enter OTP/TOTP/push app codes, or the need to register new devices. Authentication is a mission-critical service: if employees can't log into the apps or portals they use, they can't do their job. In fact, the average company loses $5.2 million annually in productivity due to account lockouts . As noted in the security section, the highest cost associated with legacy authentication comes from risk-the risk of non-compliance or data breaches, disrupted operations, threats against critical infrastructure and the loss of intellectual property . These risks only increase when we introduce complexities such as shared workstations (hot desking) and remote work. According to a recent survey, 40% of business leaders report cyber threats as the No. 1 business risk-one with the potential to decimate an organisation and, in the worst cases, make recovery impossible . As a result of the potential for loss associated with cyber threats, cyber insurance premiums have gone up as Much as 300% across high-risk industries, with new sub-limits and exclusions and a base requirement for MFA in some cases . The onus is on you as an organisation to demonstrate cybersecurity effectiveness, including MFA strategy, to make your organisational security profile more attractive to cyber insurers. Contact centre specialist Afni was able to reduce its cyber insurance premiums by 30% by demonstrating how physical encription keys reduced its risk profile. |
cyber insurance premiums have gone up as much as 300% across high-risk industries "When I'm going down by a third and others are going up by 20% or higher, that's a really big win. In fact, I estimate our premiums are nearly half of what others are having to pay." Brent Deterding,CISO, Afni |
||||||||||||
| Mobile authentication is user-friendly
Reality: Mobile authentication is complex to use and manage With almost no barriers to implementation and high user awareness of mobile authentication methods, it's common to assume that mobile authentication will be user-friendly or simple.
The truth is, passwords alone are already a burden for users and for IT. When combined with mobile authentication, these usability challenges are not eliminated-instead, they increase. According to a cross-vertical survey, 43% of organisations cite user experience as the top obstacle to using MFA . With the average employee managing 50-120 passwords and policies to force resets and time-outs, users could be authenticating hundreds of times per day-and all of this is when MFA is working as expected, not to mention forgotten passwords, OTP delay or mobile devices that are lost, with dead batteries or offline. Although end-user experience is critical to employee experience and productivity metrics, usability considerations must also extend to IT and help desk employees . From an IT perspective, 41% of organisations cite complexity as an obstacle to MFA adoption . Mobile MFA requires the support of both passwords and mobile authentication across the organisation, increasing complexity associated with registering new devices, training, integrating MFA with new apps, device management and help desk requests for password resets or lost devices. |
|||||||||||||
|
Misconception #4:
Reality: Mobile authentication creates MFA gaps While organisations may prioritise or even mandate MFA, there are almost always gaps that mobile authentication cannot fill. Where gaps exist without a comprehensive MFA strategy, most rganisations simply default to username and password. |
|||||||||||||
![]() |
Platform authenticators lack portability
In the shift away from
While platform authenticators can be a good option for users
with only one device, the average
employee today uses at least
two devices for work, not to mention any shared device |
||||||||||||
|
Misconception #5:
Reality: Mobile authentication does not support emerging regulations or modern, phishing-resistant passwordless MFA investments must provide organisations with protection that evolves as risk and compliance requirements do. To be future-proof, the MFA investment should reflect the growing regulatory requirement for phishing-resistant MFA , the need to implement Zero Trust , and modern login flows such as passwordless . Passwordless authentication implementations are designed to eliminate the security and usability weaknesses associated with passwords-but not all implementations can do both . Sending an OTP code via SMS is an easy passwordless implementation- but not a secure or phishing-resistant one. A smart card is a secure, phishing-restant passwordless implementation but not an easy or inexpensive one.
The future of passwordless is FIDO2/WebAuthn
, the combination of a phishing-resistant FIDO credential, also called a
passkey
, and the WebAuthn API that enables a
simpler and more secure sign-in to websites and apps from common devices. However,
a
passkey
is just the credential itself (a digital file), the
authenticator
is where the
passkey lives-on a phone, laptop, hardware key or other device. A synced passkey lives on a smartphone, tablet or laptop where it can be copied and synced across many devices-like we saw with mobile authentication, this “mobility” makes it easy to use, but not always secure or easy to manage. A synced passkey is vulnerable because it is so easily shared (to new devices on a cloud account or via AirDrop), making it difficult to control identity and risk. A hardware-bound passkey lives on a USB key or may give an access code at the press of a button, either way it remains separate from everyday devices but still allows easy authentication to devices and platforms-a future-proof passwordless solution that's both easy and secure . Like with mobile authentication, the evolution toward passwordless reinforces the need to separate devices being used from the authenticator. A hardware-bound passkey is a portable root of trust that allows you to prove that you possess the unique hardware device containing the cryptographic material which was registered to the user account. This, combined with a PIN and or smart card, satisfies true multi-factor authentication requirements by providing something you know , with something you are and something you have . |
In the past two years alone, the pressure to adopt phishing-resistant MFA has been added to several regulations and standards: National Security Memorandum/NSM-8 NIS2
PCI DSS v4.0
FTC standards
|
||||||||||||