The many ways to hack 2FA

Roger A. Grimes · Network Security · 2019

As the days of pervasive password authentication are starting to wane, administrators and end users are increasingly turning to stronger types of authentication such as two-factor authentication (2FA) and multi-factor authentication (MFA). All other considerations considered equal, MFA solutions (which include 2FA) are usually stronger than single-factor authentication (1FA) solutions such as the ubiquitous duo of username and password. This is generally agreed upon by all computer security professionals. People are increasingly turning to stronger types of authentication such as two-factor authentication (2FA) and multi-factor authentication (MFA). But somewhere along the way, many people have come to associate MFA solutions with being far less hackable or even unhackable. Nothing could be further from the truth. In fact, it's possible to use nothing more than a simple phishing email to easily bypass many beloved MFA solutions, says Roger Grimes of KnowBe4.

Read the paper · More papers on PaperTik