Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 319, Issue 2IT NewsMFA

Today's 'Good Enough MFA' Should Be Phishing-Resistant

Security Boulevard, Thursday, October 10th, 2024

In today's world, we can't escape the daily headlines about data breaches, hacks, and cyberattacks. It's everywhere we look. And, when it comes to multifactor authentication (MFA), the old saying 'I don't have to be faster than the bear, I just need to be faster than the other guy,' applies.

Having MFA can make you feel like you're the fastest runner, but you can turn into 'the other guy' overnight. All it takes is a threat actor buying a new man-in-the-middle (MITM) attack kit or pivoting from one target to an internal, 2-factor (2FA) protected resource to bypass basic MFA. It's just that easy.

And yet, surprisingly, not every organization has even implemented multi-factor authentication (MFA), and even fewer have adopted phishing-resistant solutions. This makes us wonder:

  • Why isn't MFA deployed everywhere?
  • Why is basic MFA gaining more traction?
  • Why don't we see more widespread use of phishing-resistant authentication?

And, now that October is here and we are recognizing Cybersecurity Awareness Month, what better time to dive into these questions and understand why settling for 'good enough' (or just simply 'turning it on') when it comes to MFA just isn't sufficient anymore.

more →  ·  More from MFA →