Hacking Multi-Factor Authenticators
Hacking Multi-Factor Authenticators
Hacking Multi-Factor Authenticators
Multi-Factor
Authenticators
26 October 2022
Date and time
sophisticated adversaries.
Cybersecurity is important because it
protects all categories of data from theft
The real problems behind computer security
and damage
involve people and making appropriate risk
decisions
Kevin Mitnick
What is MFA and Types
What is MFA?
Multi-Factor Authentication is a security concept that simply involves the use of
Examples:
Swiping a bank card at the ATM and then entering a PIN
Presenting an ID card and then scanning a fingerprint
Captcha verification along with phone number verification
What is MFA and Types
Types of Authentications
When 2 or more of these combines, that becomes a Multi-Factor Authentication plan
Eg: Security Questions, PIN Numbers Eg: ID Cards, Phone Eg: Retinal Scan, Fingerprints
2 Are MFAs as Safe as you Think ?
Are MFAs as Safe as you Think ?
Conclusion: No, if one believe that you have a solution that is hackproof, they are either lying to you or naive.
Are MFAs as Safe as you Think ?
Social Engineering
Fake Authentication
Recovery Questions Attack
Social Engineering Tech Support
Are MFAs as Safe as you Think ?
Technical Manipulation
Session Unique Identifier Prediction
Man in the Endpoint Attacks
Malicious MFA Software of Hardware Modification
Duplicate Code Generators
Skimming Attacks
Subject Hijacks
Brute Force Attacks
Buggy MFA
Are MFAs as Safe as you Think ?
Physical Attacks
Stolen Biometrics
Re-created Biometrics
Office of Personnel Management
Cold Boot Attacks
Are MFAs as Safe as you Think ?
Mixture of Methods
Session Hijacking
SIM Swap Attacks
Downgrade and Recovery Attacks
3 Picking the Right Solution
Picking the Right Solution
Cyber breach and attacks evolve day to day and it must be educated on
that. Do not trust any vendor who says it is unbreakable.
THANK YOU!