The Evolution of Authentication

Blog

The Evolution of Authentication

Grace Daniel

Grace Daniel

Product Marketing Manager

Share on linkedin
Share on facebook
Share on email

Since the 1960s passwords have been used to verify user identity. On the other hand, the first known data breach occurred in 1961. The two-factor authentication (2FA) that we know today was first made available by the late 1980s. To provide stronger security for accounts and data, multi-factor authentication (MFA) was introduced. With multi-factor authentication, a user needs to provide multiple pieces of evidence to log in to an account: something the user knows (like a password), something the user has (like a token), or something the user is (like a fingerprint). Authentication has truly come a long way. However, adversaries also continue to devise sophisticated tactics to get hold of accounts and data for exploitation and financial gains, and sometimes for mere show of power.

 

As the threat landscape evolve, so as the need for stronger authentication. Gone are the days when passwords provide enough security. Unfortunately, passwords are still the primary mode of authentication to this day. With attacks becoming more and more sophisticated, even the use of two-factor authentication (2FA) such as SMS one-time password (OTP) no longer provides sufficient protection. Here’s a rundown of the attacks SMS OTP is susceptible:

SMS OTP Interception. SMS OTP from a malware infected mobile phone is intercepted and rerouted.

SIM Swap. An attacker impersonates the victim, and tricks the mobile phone service provider into transferring the ownership of the victim’s phone number to the attacker.

SIM Cloning. This attack is more sophisticated. An attacker clones the victim’s SIM card remotely by abusing over-the-air (OTA) communication, which sends updates to the SIM, or by using a surveillance toolkit.

 

The best practice to protect accounts and data is to use multi-factor authentication. In the event user credentials are stolen, they will be useless to the attacker as it may not be possible for the attacker to have access to all three of the above mentioned evidences. But enforcing stronger security may lead to poor user experience. When choosing a multi-factor authentication solution, it is important to keep these three considerations in mind:

Flexible. A wide array of authenticators are available to suit different levels of security required, and support different use cases.

Future-Proof. The solution should not only be able to cater to existing requirements, but for future needs as well.

Seamless User Experience. It should provide seamless user experience no matter the level of security required.

 

Information about our MFA solution can be found here.

Want to know more about MFA?

Provide us with your contact details and we will get in touch with you.