Why Phishing-Resistant MFA Is No Longer Optional: The Hidden Risks of Legacy MFA

October 24, 2024 at 07:38AM The article emphasizes the urgent need for organizations to adopt phishing-resistant multifactor authentication (MFA) as ransomware payments soar, with an average increase of 500%. Legacy MFA systems prove inadequate against evolving cyber threats fueled by Generative AI. Implementing advanced, biometric-based solutions is essential to combat this growing risk. ### Meeting … Read more

Amazon says 175 million customers now use passkeys to log in

October 16, 2024 at 09:07AM Amazon reported that over 175 million customers now use passkeys for faster, passwordless sign-ins, enhancing security through cryptographic keys linked to biometric controls. The feature, initially introduced a year ago, is expanding to other services like AWS and Audible. The FIDO alliance has also announced a specification for portable passkeys. … Read more

Google brings better bricking to Androids, to curtail crims

October 7, 2024 at 11:04PM Google has globally rolled out three new Android features to deter phone theft. The Theft Detection Lock activates if a phone is taken and moves at high speed, the Offline Device Lock works if the device is offline for a long time, and Remote Lock allows users to lock stolen … Read more

Google Now Syncing Passkeys Across Desktop, Android Devices

September 20, 2024 at 09:48AM Google introduced passkey support in 2022 for Android and Chrome, allowing users to authenticate with biometric instead of passwords. Users can now save passkeys to Google Password Manager from Windows, macOS, Linux, and Android, syncing them across devices for easier sign-ins. End-to-end encryption and a new Google Password Manager PIN … Read more

Google Password Manager now automatically syncs your passkeys

September 19, 2024 at 01:22PM Google announced that passkeys in Google Password Manager now sync across Windows, macOS, Linux, Android, and ChromeOS devices. Passkeys offer biometric authentication for secure and convenient access. Users can now add passkeys from various devices, with ChromeOS in beta and iOS support coming soon. Google also introduced a new PIN … Read more

India contemplates compulsory dynamic 2FA for digital payments

August 1, 2024 at 11:37PM India’s central bank proposed new requirements for second authentication factors for digital payments, aiming to move beyond SMS OTP to consider biometrics, pins, passphrases, and hardware or software tokens. It prioritizes dynamic generation and single-use to enhance security, allowing banks to choose the AFA while mandating compliance and exceptions for … Read more

Goodbye? Attackers Can Bypass ‘Windows Hello’ Strong Authentication

July 23, 2024 at 03:52PM Microsoft’s Windows Hello for Business (WHfB) authentication, previously believed to be resistant to phishing, was found vulnerable to downgrade attacks. Security researcher Yehuda Smirnov discovered the flaw, leading to a fix by Microsoft. The company introduced a new Conditional Access policy to enforce phishing-resistant authentication, safeguarding against downgraded methods. From … Read more

Google Advanced Protection Program gets passkeys for high-risk users

July 10, 2024 at 06:39AM Google has introduced passkeys for high-risk users enrolling in the Advanced Protection Program, offering strong account security. Passkeys are tied to specific devices and provide a more secure alternative to traditional passwords, using biometric sensors or PINs. High-risk users can enroll using passkeys, ensuring protection against unauthorized access and phishing … Read more

Selfie-based authentication raises eyebrows among infosec experts

July 8, 2024 at 01:39AM The use of selfies for online identity verification is gaining traction due to increased digital engagement sparked by the pandemic. However, concerns arise regarding its effectiveness and security. While some advocate for liveness checks and biometrics as more robust methods, regulatory and privacy gaps persist, prompting the need for comprehensive … Read more

How MFA Failures are Fueling a 500% Surge in Ransomware Losses

July 2, 2024 at 07:07AM The cybersecurity threat landscape has seen a substantial rise in average ransomware payments, with increases over 500%. The surge is attributed to cybercriminals better targeting organizations for larger ransom payments, as well as the utilization of Generative AI in creating convincing phishing attacks. Implementing next-generation MFA technologies, including biometrics, is … Read more