3 ms·
I don't think it is pedantic at all. I have been in the most technical parts of the infosec industry for 15+ years. The usability of security features and user
by bitexploder 5y ago
I don't think it is pedantic at all. I have been in the most technical parts of the infosec industry for 15+ years. The usability of security features and user education is the iceberg. Getting them to use MFA and such are the tip.
- 2snakes 5y agoI think you're so deep you don't see the forest for the trees. I doubt you are right about people getting compromised with MFA all the time. Especially with hard tokens. If you can substantiate that claim, I might learn something.
- bitexploder 5y agoI see it all the time in incident response summaries. It’s happened to our own customers many times. Standard “enter a few numbers” MFA is easy. Phishers collect it just like they get passwords. It raises the bar slightly. Hardware based MFA is a different situation. So it has to be qualified. But normal people logging intoxicated their bank accounts don’t have hardware MFA tokens. Most security professionals don’t even use them everywhere. We run phishing simulations and red teams dozens of times a year for F500 and high tech firms. MFA tokens are never what saves someone. Ever. We always get in. Often with phishing or smishing. I talk with many other folks that do red teams and phishing engagements.it’s of course anecdotal, but it’s a rather large and high impact customer set across people I know and our own customers. It will save some people some of the time. But not like people think. If my own deep experience and what I have seen in the field doesn’t convince you, that’s fine. I’m just sharing what I know to help people understand.