Multifactor Authentication Fatigue – Daniel Thanos, Arctic Wolf Labs
Daniel Thanos, vice president of Arctic Wolf Labs, explains why multifactor authentication (MFA) fatigue has already set in despite best cybersecurity intentions.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Daniel Thanos. Who's Vice president and head of Arctic Wolf labs and we're talking about multi-factor authentication but not so much the fact that everybody should get it and needs it. But we've already encountered fatigue with it.
It's amazing Daniel. Welcome to the show. Hey, thanks for having me on.
Big fan of the show and we have been telling people to adopt MFA for several years now with mixed success and but now it looks like people are actually starting to listen and we're encountering a lot of this and maybe it's just me, but I feel like a lot of it is done poorly and people are getting someone annoyed. So What is the right approach to this whole thing because how many times can I be asked to log into a website with a passcode sent to my phone before somebody figures out, it's me. Excuse me.
Yes. That's a great great question and kind of great framing of the issue. There has been considerable more uptake of MFA, but the reality is And if its series always learn to adapt, right they learn to exploit weakness and technology and in humans.
And in this case the weakness, they're exploiting especially when you're doing kind of a more modernized solutions which are essentially sending you a push to your phone and say hey is that you click? Yes, right. What they're doing is they're just flooding you the point where someone gets really tired of it and just surrender then they literally just click yes or usually what happens is they think that they're clicking.
No, but because I've been doing it so many times they ended up, you know touching. Yes, right. And so the bad guys have figured out that there's always gonna be a certain percentage and your user population that if you annoy them enough, they're either by error or by just sharing exhaustion.
They're gonna click that. Yes. Um, so when it comes to those types of attacks really there, there's enough you there's like another tweak if you will on kind of like push type oriented MFA and that is called a number matching authentication on MFA.
So if you like use Microsoft authenticator for example in the past more currently You can enable an option where essentially it sends you a push but that push is is gonna have like a number on it. Right or it's gonna ask me to select a number that goes along with push. So therefore you have to consciously, you know be in front of the service you're authenticating to to match kind of match those numbers.
And so therefore if you're kind of like out and about and you know getting MFA fatigue that's less likely you're gonna pick the right numbers. Yeah, you have no idea because you're not seeing you're not seeing in front of the service and usually bad guys. Once they understand that this is a type of thing.
That's enabled. They're not like, you know, they're gonna go off to another Target because they know they're not gonna they're not gonna get that easy. Yes in the process.
And of course, there's many different types of MFA. You just alluded to one which is like, you know, you keep on getting an SMS code to your to your phone or whatever that you have to type in those types of attacks are kind of less susceptible to like fatigue oriented attacks, but what the artists acceptable to is is far more important attacks that have to do with like, you know malware that you're gonna get on a phone that will intercept those things or you know, fake acts which will kind of give you get you to kind of get over that code. So then they can kind of take over your account.
There's many methods involved in that type of MFA such that obviously the pushing that that is better or you know, our physical token is better. I always recommend for like, you know, highly Not Mission critical or highly secure systems that you're having a hardware base token is you know, like the final two baseball game is not a bad thing. Right?
It's like a highly privileged system. That's also something very good to look at if you want that extra piece, you know of assurance. Will therefore there be tears of MFA processes that will be tuned to specific risk levels or is there kind of like one MFA process that is better than others and this is the one that will be most widely used.
There is they're just gonna be a lot of MFA nuances here. I think the reality is as bad guys kind of shift tactics. It always just forces organizations and individuals to respond.
What I will tell you is if you're doing like the the number matching multifactor, um, that's that's a pretty good approach right because that gives you the convenience it gives you the convenience of push. It makes it easy to kind of roll out in a large organization a small organization. And it's not going to be kind of subject to this to this class of attack.
And if you can get something like that, even if you're kind of going back to an app that I'm kind of gives you like a one-time code or a one-time password that you have to type in even that's better and then kind of just clicking, you know, yes by default because that's just becoming very easy for the bad guys to kind of kind of get through. So yeah, like the answer your question. I still think that given the last two methods I discussed that it still good enough to give you more than a pervasive level of protection.
But in some organizations again that are have like highly privileged systems having that physical Tolkien is not a bad idea. And we read some sort of threshold where everybody's basically saying security situation has gotten the point where we must absolutely have MFA regardless of what kind of annoyance the inner user receives, right? Yeah, you have to right because it's just not enough with passwords anymore.
When you look at the vast majority of different types of attacks that happen. We're fishing through rant somewhere. Um through account takeovers and all the automated type of attacks that we see it just has proven that it you'd absolutely need to have MFA as a base level control.
It's no longer sufficient just to kind of rely on, you know, Legacy oriented passwords and password management. It just doesn't it doesn't work anymore and there's lots of reasons for this regardless of you know, how much an organization May educate users the realities a lot of users even in the face of that education will do silly things like take their credentials corporate credentials and and use them on like public sites or less than secure sites or dodgy sites. And then those things get reached and you know, the that is Trivial to kind of use that account in an attack and an initial access broker will sell that credential than a ransomware.
Provider will use that as an in so definitely what we see is like a good portion of attacks can be mitigated successfully if you just use that, okay. Initially, there was a lot of concern about the end customers experience, but I have to wonder also if that was a bit of a Dodge because MFA for a lot of folks. They kept saying it's hard to implement.
It's hard to manage. There's a lot of pieces. Is it getting simpler to implement or where are we on that curve?
I think it I think inevitably it's definitely much simpler than what it was, especially with the Advent of things like smartphones and and essentially all of this becoming software defined and Pretty trivial to deliver. Yes, you know going back a couple generational technology, but that's true. Like it was not it wasn't easy to do but here's the thing like this technology has also commoditized and consumerized right like Um, my father knows how to use two Factor authentication, right?
And you know, he's a senior he's retired and he has no problem using MFA. He knows what it is and and he's eager to do it. And so that to me is kind of like You know a good sign of where things have gone consumers consumers can understand it then a user and an Enterprise can understand it as well and can use it and the technology of a lot of the you know services that you kind of get built in these days.
A lot of especially public cloud service providers are or many others. It's kind of it's become a commodity. It's just it's just there for you to use.
Not even silly not to. I think my father-in-law knows to hand the phone to my son when he wants to deal with this, but that's a different story. As we go along we hear a lot about passwordless approaches to Identity and identity management.
So as you kind of look at this whole Space, how do you think it will continue to evolve? I mean is this a moment in time towards a greater thing that we're working towards and what does that look like? Yeah, I do think that's like that's definitely the path that were that were on essentially push.
Push notifications are are you know the beginning of that and then just kind of having you know, cryptographic credentials that are kind of provision to specific assets together with Dynamic push face. Together with some sort of challenge call type authentication I think is where we're going to go more use of Biometrics as that technology kind of disseminates out to the broader industry. I think even just using the bio authentication on our various mobile devices will be something that even Enterprises can begin to leverage.
I see Technologies kind of being baked into like, you know, Microsoft operating system and and their facial recognition attack that's becoming more distributed out there. All of these factors combined together. I think are are what are going to drive passwords to kind of, you know, go away as a standard nothing thinking over time.
one other techniques of the bad guys using to get around MFA and you know, because clearly they're in the sea in this trend themselves, and I'm sure you know other than Brute Force attacks that you describe that they obtain anything else that we should be keeping an eye out for Well, I think right now honestly to be the be truthful like depending on the class of MFA. So for if you're like kind of using what I call more like first gen MFA or Poor Man's MFA, you know, who am I miss SMS codes and emails and all that. Well that's stuff.
They can already kind of tap and hijack with various types of you know malware or they can spoof aside and get you know, put in, you know, put in a code if it's like being Dynamic it generated and I wasn't to steal your session and do all types of stuff. So I kind of work that aside that's kind of well-known. We're kind of going to like these types of like, you know, push oriented authentications where there's acceptable time of Faith fatigue.
Definitely that's that's where the action is right now. It's it is it is MFA tea and to litigate that as we said you want to essentially do that number matching or kind of like an extra challenge which just basically says, you know, here's the push, you know, which code is it? So you definitely want something like that.
And I think that will take care of kind of what adversaries are doing for now, but the reality is, you know over time we will have to see right like definitely I've seen more exotic type threats that for example that can land on mobiles or that can land on desktops where I wouldn't be too surprised if they kind of trigger an authentication and then depending on what they've been able to put on your device. They may be able to grab screenshots. Right?
And it kind of see what's what you know, what's appearing or what you're doing. So, you know, we'll see kind of where things go, but I think that is pretty that is pretty more exotic in nature. And I I think right now with where the attack is at if you just enable this extra feature kind of found on a lot of these MFA system.
You'll you'll you'll be fine. I think for the next little while. I sometimes scratch my head because clearly I can be walking down the street by some store and somehow or other somebody knows that I might be interested in that I start getting stuff in my email and threads and text.
So that's a different somebody knows where I am and can try my location. That's a different issue. Now now we're getting issue of like, you know, privacy and data Brokers the reality is and of course Apple has made a has been one vendor.
I think that's made the most enrolled into that area. But the reality there is that a lot of the apps we use get all types of access and sometimes we're granting that access again. It's like, it's me what I call the I you know, I haven't paid a hundred percent attention to kind of what I'm clicking on but a lot of apps when they install on your on your device your phone they ask for like crap load of permissions or like a lot of permissions and people just say, yes, they don't pay attention to what it's asking for.
Basically what it's doing is it's you're handing it a lot of telemetry you're handing a GPS Telemetry. A lot of people click. Yes to allowing the app to run in the background and continually access their GPS.
They're clicking. Yes to it kind of looking at your browsing history and a bunch of other things and and then of course it quickly correlates when you're in front of a store based on your GPS location and when you've given it access to your emails SMS messages in a whole bunch of other things and quickly connect some dots and it flashes you an advertisement and then there's someone in the in the date of broker Market that is basically bidding to get that data day in and day out in order to serve up that out to you. So can that they use all that data that we're already collecting to that indicate the fact that I am me and I'm accessing this thing already because it seems like they already have all that data.
Well you bring up a good point in terms of the future, you know in terms of what that means. I have I've heard of authentication systems that are based on proximity based on your gate and how you walk that, you know again, like if you're if you're allowing something onto your device that's less than trusted and you're giving it extraordinary access. It's not far fetched to assume that adversaries will begin to figure out how to use that but I don't think we're quite there yet.
All right. It's a never-ending game of spy versus spy Daniel. Thanks for being on the show.
All right was real pleasure. Thank you. All right back to you guys in the studio.