John Gunn, CEO, Token
2 minute read
The comparison between next-generation MFA and legacy MFA comes down to a single question. What does an attacker need to defeat it?
Legacy MFA adds a step to the login process. If that step produces a value that can be intercepted, forwarded or socially engineered out of a user, the step exists but the protection does not. Next-generation MFA is designed so there is nothing to intercept. The sections below cover each core weakness of legacy MFA and the next-generation property that eliminates it.
SMS codes, time-based OTPs and push notifications share a single vulnerability. They all produce something transferable. An attacker who positions a proxy between the victim and the real login portal captures the code or push approval as it passes through and replays it before it expires.
The exchange takes seconds. The code is valid. The login is legitimate. The victim sees nothing wrong.
Next-generation MFA closes this through credential binding. FIDO2-compliant authenticators generate a response tied to the specific domain the user is logging into. A proxy operating on a different domain cannot produce a valid challenge. A biometric authenticator goes further. A live fingerprint match is required before any credential is generated. No code leaves the device. There is nothing to relay.
Push notifications and OTP codes both require a human decision at the point of authentication. An attacker who can convince the user to approve a push or share a code bypasses every technical control in place.
MFA fatigue is the systematic version. The attacker uses stolen credentials to trigger repeated push notifications until the user approves one out of exhaustion or confusion.
The 2022 Uber breach followed this exact pattern.
Vishing is the directed version. The attacker calls the victim, impersonates IT support and explains why approving the pending push is necessary. The approval is genuine. The session it opens belongs to the attacker.
Next-generation MFA removes the human decision from the authentication chain. A biometric authenticator requires a fingerprint tap on a device bound to a specific domain. There is no push to approve, no code to share and no scenario in which social pressure produces a transferable factor.
Standard hardware tokens are separate objects. They get lost, forgotten at home and left plugged into the laptops they are supposed to protect. A token left in a laptop can be used by anyone with physical access to it. There is no identity check at the device level.
Some vendors recommend buying two tokens per user because loss rates are high enough to require backup stock. The object that anchors authentication is routinely unanchored.
A wearable biometric authenticator changes this. It is always with the user. It cannot be left behind without the user noticing. And it responds only to the enrolled user’s fingerprint. Possession alone is not enough to authenticate.
Of course, MFA of any type is a much stronger and much more reliable way to protect users and organizations from many kinds of cyberattacks than using passwords. However, the doubling of successful attacks and the massive financial losses demonstrate that legacy MFA is no longer safe or effective. To protect against unauthorized users, organizations need much more than traditional MFA. They need Biometric Authentication. It is cold and evil out there in the cybercriminal land, and the unprepared pose easy targets.
As seen in Bleeping Computer
How a Phishing Relay Attack Works Phishing relay attacks do not break authentication. They sit in the middle of it. A phishing relay attack inserts an attacker-controlled proxy between the victim and the legitimate login portal. The victim believes they are on the real site. Every credential they enter goes to the attacker first. The sequence is predictable. The victim receives a phishing email linking to a page that looks identical to the real login portal. They enter their username and password. The attacker’s proxy forwards these to the real site immediately. The real site triggers an MFA challenge. The proxy mirrors that challenge back to the victim. The victim enters their six-digit code or approves a push notification. The attacker forwards the response. The real site authenticates the session. The exchange takes seconds. The victim has logged in. The attacker has the session.
What is Legacy MFA? Legacy MFA are solutions such as OTP over SMS and OTP via mobile apps that are 20-year-old technology. While using this technology is better than no-MFA, cybercriminals have developed sophisticated techniques and tools that regularly defeat legacy multifactor authentication (MFA). MFA significantly enhances account security, but not all MFA is created equal, and attackers are exploiting human vulnerabilities resulting in billions of dollars of losses. Here are the most common TTP used by cybercriminals.
Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.