Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News

6/1/2016
11:00 AM
Sean Martin
Sean Martin
Slideshows
Connect Directly
LinkedIn
RSS
E-Mail
100%
0%

4 Steps to Achieve MFA Everywhere

What would it take to move authentication processes beyond sole reliance on passwords? Here's how to begin the journey.
Previous
1 of 6
Next

It’s one of the toughest challenges companies face in today’s connected and mobile world: Figuring out how to grant the least amount of privilege to allow users to get their jobs done while not putting their network and data at risk. Get this calculated balance wrong, and the teeter-totter tips in one direction or another—and neither option is great.

Given that 63% of confirmed data breaches (as reported in the Verizon DBIR) involved weak, default or stolen passwords, it should be painfully obvious that a reliance on passwords to overcome this challenge is not the best answer. Reliance on a single form of authentication—as Centrify’s CEO Tom Kemp puts it—“is brain-dead.”

“If a password is stolen, people can literally walk through the digital front door,” added Kemp during his opening talk at his company’s CentrifyConnect user conference.

Michael Hayden, retired U.S. General and the former National Security Agency Director, shared a similar position during his CentrifyConnect keynote: “Authentication and identity ought to be a very big deal for organizations.”

Andras Cser, vice president and principal analyst, security and risk management, at Forrester Research, was more direct with his view: “Passwords are dead—multi-factor authentication is a must.”

The truth is, there are a number of weaknesses associated with passwords—and they are becoming increasingly inadequate.

Cser also shared the following about passwords; they are or can be…

- Shoulder-surfed
- Decrypted (within milliseconds if less than 12 chars)
- Breached
- Reused
- Shared

As networks become software-defined, as systems connect with other systems, business-process orchestration takes over the core of a company’s operations, organizations need to not only consider human accounts for authentication, but also account for non-human (system) accounts when managing privileged accounts and privileged command execution. Of course, as we begin to introduce additional internet and network-connected devices and sensors as part of the swelling wave of Internet of Things, this authentication challenge will only become more complicated.

It’s should come as no surprise that most view the idea of implementing multi-factor authentication (MFA) “everywhere” to be an expensive, difficult and cumbersome endeavor.

Still, Kemp is on a mission to make “MFA Everywhere” a reality. His position is driven by the sheer fact that attacks are able to spread extremely easily by stealing usernames and passwords—and this reality isn’t going to change any time soon.

“This risk can be eliminated with the use of MFA everywhere,” said Kemp during an interview.

What would it take to make “MFA everywhere” a reality, moving authentication processes beyond sole reliance on passwords? Kemp, and some of his company’s users and conference speakers shared their thoughts on how to get started down the path to achieve MFA everywhere by following these four steps.

Note: The team at imsmartin would like to thank the team at Centrify for their contributions that led to this slide collection.

 

Sean Martin is an information security veteran of nearly 25 years and a four-term CISSP with articles published globally covering security management, cloud computing, enterprise mobility, governance, risk, and compliance—with a focus on specialized industries such as ...
View Full Bio

Previous
1 of 6
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
SeanM902
50%
50%
SeanM902,
User Rank: Apprentice
6/2/2016 | 7:09:59 PM
Re: MFA All The Things Is Possible
Thank you for your comment AdamE896 .. I appreciate your thoughtful response, especially your calls to action for organizations to use MFA and for vendors to make it easier to use.
AdamE896
50%
50%
AdamE896,
User Rank: Apprentice
6/2/2016 | 2:29:59 PM
MFA All The Things Is Possible
I think this article is a fantastic start to talk about MFA. I would challenge organizations to go futher than adding MFA to critical systems. Most users want an option other than application passwords. The main roadblock to user conversion for MFA is ease of use. If MFA is as easy as or easier than password based authentication, users would adopt that process. Let's face it, everyone hates passwords. With a proper authentication alternative and good risk based adaptive security, we can MFA all of the things.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25596
PUBLISHED: 2020-09-23
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it twice to the guest. T...
CVE-2020-25597
PUBLISHED: 2020-09-23
An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may not turn invalid. Logic in the handling of event channel operations in Xen assumes that an event channel, once valid, will not become invalid over the life time of a guest. Howeve...
CVE-2020-25598
PUBLISHED: 2020-09-23
An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Read, Copy, Update) mechanism is a synchronisation primitive. A buggy error path in the XENMEM_acquire_resource exits without releasing an RCU reference, which is conceptually similar...
CVE-2020-25599
PUBLISHED: 2020-09-23
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory a...
CVE-2020-25600
PUBLISHED: 2020-09-23
An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of usable event channels for 32-bit x86 domains vs 64-bit or Arm (either bitness) ones. 32-bit x86 domains...