Next-Generation MFA vs Legacy MFA

John Gunn, CEO, Token
2 minute read
Legacy MFA has security gaps

The comparison between next-generation MFA and legacy MFA comes down to a single question. What does an attacker need to defeat it?

Legacy MFA adds a step to the login process. If that step produces a value that can be intercepted, forwarded or socially engineered out of a user, the step exists but the protection does not. Next-generation MFA is designed so there is nothing to intercept. The sections below cover each core weakness of legacy MFA and the next-generation property that eliminates it.

Phishing and Relay Attacks

SMS codes, time-based OTPs and push notifications share a single vulnerability. They all produce something transferable. An attacker who positions a proxy between the victim and the real login portal captures the code or push approval as it passes through and replays it before it expires.

The exchange takes seconds. The code is valid. The login is legitimate. The victim sees nothing wrong.

Next-generation MFA closes this through credential binding. FIDO2-compliant authenticators generate a response tied to the specific domain the user is logging into. A proxy operating on a different domain cannot produce a valid challenge. A biometric authenticator goes further. A live fingerprint match is required before any credential is generated. No code leaves the device. There is nothing to relay.

Social Engineering and the Human Factor

Push notifications and OTP codes both require a human decision at the point of authentication. An attacker who can convince the user to approve a push or share a code bypasses every technical control in place.

MFA fatigue is the systematic version. The attacker uses stolen credentials to trigger repeated push notifications until the user approves one out of exhaustion or confusion. 

The 2022 Uber breach followed this exact pattern.

Vishing is the directed version. The attacker calls the victim, impersonates IT support and explains why approving the pending push is necessary. The approval is genuine. The session it opens belongs to the attacker.

Next-generation MFA removes the human decision from the authentication chain. A biometric authenticator requires a fingerprint tap on a device bound to a specific domain. There is no push to approve, no code to share and no scenario in which social pressure produces a transferable factor.

Physical Hardware and Device Security

Standard hardware tokens are separate objects. They get lost, forgotten at home and left plugged into the laptops they are supposed to protect. A token left in a laptop can be used by anyone with physical access to it. There is no identity check at the device level.

Some vendors recommend buying two tokens per user because loss rates are high enough to require backup stock. The object that anchors authentication is routinely unanchored.

A wearable biometric authenticator changes this. It is always with the user. It cannot be left behind without the user noticing. And it responds only to the enrolled user’s fingerprint. Possession alone is not enough to authenticate.

Recommendation

Of course, MFA of any type is a much stronger and much more reliable way to protect users and organizations from many kinds of cyberattacks than using passwords. However, the doubling of successful attacks and the massive financial losses demonstrate that legacy MFA is no longer safe or effective. To protect against unauthorized users, organizations need much more than traditional MFA. They need Biometric Authentication. It is cold and evil out there in the cybercriminal land, and the unprepared pose easy targets.

Stay Identity Assured

Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.