3 ms·
People get compromised with MFA all the time. It’s like 1/10th of a societal level solution. The real biggest part is also the hardest and that is education. Pa
by bitexploder 5y ago
People get compromised with MFA all the time. It’s like 1/10th of a societal level solution. The real biggest part is also the hardest and that is education. Password managers, spotting phishing, spotting scam calls, using MFA, updating your software regularly, patching your ancient home router, etc. It takes a lot and these are all likely vectors you will get popped as a regular user in home equipment. There is no cure all and even as someone with 15 years of experience in the most technical parts of information security I have no simple solutions. Don’t use computers lol.
- giantg2 5y agoMost routers today have automatic patching schedules, so at least that one is getting better.
- jvanderbot 5y agoyes they do get compromised, but that doesn't mean you shouldn't use it. It also doesn't mean that's all you should use. If all of society used 2fa, we'd be much better, which is all OP was saying. Also, 1/10 can still be the biggest factor. but this is getting pedantic
- bitexploder 5y agoI don't think it is pedantic at all. I have been in the most technical parts of the infosec industry for 15+ years. The usability of security features and user education is the iceberg. Getting them to use MFA and such are the tip.
- 2snakes 5y agoI think you're so deep you don't see the forest for the trees. I doubt you are right about people getting compromised with MFA all the time. Especially with hard tokens. If you can substantiate that claim, I might learn something.
- bitexploder 5y agoI see it all the time in incident response summaries. It’s happened to our own customers many times. Standard “enter a few numbers” MFA is easy. Phishers collect it just like they get passwords. It raises the bar slightly. Hardware based MFA is a different situation. So it has to be qualified. But normal people logging intoxicated their bank accounts don’t have hardware MFA tokens. Most security professionals don’t even use them everywhere. We run phishing simulations and red teams dozens of times a year for F500 and high tech firms. MFA tokens are never what saves someone. Ever. We always get in. Often with phishing or smishing. I talk with many other folks that do red teams and phishing engagements.it’s of course anecdotal, but it’s a rather large and high impact customer set across people I know and our own customers. It will save some people some of the time. But not like people think. If my own deep experience and what I have seen in the field doesn’t convince you, that’s fine. I’m just sharing what I know to help people understand.