Based on the ready availability of AI-based voice cloning, we declare voice biometric authentication to be utterly valueless.
Ressourcen
1 bis 18 von 19 ressourcen angezeigt
Britain's National Cyber Security Centre recently issued a lukewarm verdict on passkeys as an authentication solution. We explore the problems with WebAuthn, including account recovery, spotty availability, inconsistent implementation, and lack of…
We define multi good factor authentication, which is the idea that not all authentication factors are equal. We discuss the importance of considering authentication strength and the contextual nature of trust.
Cybersicherheit ist kein Alles-oder-Nichts-Prinzip. Automatisierung und kürzere Zertifikatslaufzeiten verbessern den Schutz.
Not all forms of MFA are equally secure. In this episode, we describe the differences between the more secure and less secure forms of MFA.
Sectigo Blog
Warum sprechen wir nach all den Jahren immer noch über die Grundlagen der Cybersicherheit?
Trotz jahrelanger Sensibilisierung bleiben sichere Passwörter, MFA und Phishing-Warnungen in unserer schnelllebigen Welt unerlässlich.
White hat researchers have raised concerns about FIDO 2 (AKA WebAuthn). We explain.
New malware photographs users' faces to defeat authentication mechanisms. Biometrics are not "secrets."
A social engineering attack to steal a one-time password (OTP) to enable unauthorized access is further exploited by a cloud backup feature.
Recent high profile attacks that were enabled by defeating MFA. We explain the concept of MFA fatigue and why it is an enabler for these attacks.
A recent article from Brian Krebs advances the idea that using OTP MFA may actually be a liability to security. We explain that reasoning.
In this episode we clarify the difference between OTP services and passwordless authentication.
A recent FBI warning cautions organizations about exploits based on misconfigured DUO MFA. We explain this exploit and why it is noteworthy.
We explore out-of-band phone calling as a MFA method, including, what attacks it defends against successfully, and what attacks can circumvent it.
A new attack allows cloning of the Google Titan secure key. we describe this attack and its implications for Titan and other secure keys.
The SolarWinds supply chain attack i includes unusual manipulations of digital identity and certificates. We explore these aspects of the attack.
In our ongoing examination of MFA, we examine authentication through soft-token OTP (one-time passcode) and compare it to SMS tokens and hard tokens.
Hard tokens are an old multi-factor authentication (MFA) form factor, still in use today. We examine the strengths and weaknesses of hard tokens.
Benötigen Sie Hilfe?
Benötigen Sie Hilfe beim Kauf? Kontaktieren Sie uns noch heute, um Ihr Zertifikat sofort zu erhalten.