Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

11/15/2017
02:30 PM
Seth Ruden
Seth Ruden
Commentary
50%
50%

Who Am I? Best Practices for Next-Gen Authentication

By their very nature, antiquated, static identifiers like Social Security numbers and dates of birth are worse than passwords.

There is no ignoring it: our financial security is compromised daily. Many security professionals reading this wouldn't hesitate to recount all the breaches they've been a part of as consumers: merchant breaches in which replacement cards forced you to update your linked accounts, or data compromises when personal information was stolen and identity theft protection was provided, forcing you to consider freezing new credit originations.

These are only the ones we know about, however. A recent report from SkyHigh Networks concluded that up to 7% of all Amazon S3 servers leave volumes of exposed via "public access" configuration. Consider the residual risk of all the data breaches we've historically been exposed to and the totality of this vulnerability becomes immense. Back in the first quarter of 2014, I suggested we were experiencing data breach fatigue; today it's data breach exhaustion, and consumers may now feel powerless.

These consumer attitudes are reflected in ACI Worldwide's "Global Consumer Trust and Security Perceptions Survey," which revealed that an average 65% of consumers across 20 countries stop shopping with a merchant or a retailer once they experience fraud or a data breach. In select regions like Brazil and Mexico, this figure rises as high as 86% and 84%, respectively. It is a risk that few are willing to take and a stern lesson in the strategic importance of data security across the enterprise in 2017.

We must ask ourselves, as both consumers and enterprise security professionals: What exactly is compromised here? What information falls into the hands of an attacker and how could they use it to attack me? As we're compromised once, twice, multiple times, we are falling under greater risk from hackers and fraudsters.

Typically, most concerning for consumers is the demographic data that is baked directly into authentication procedures. If an attacker has the relevant non-public personal information, they can coordinate illegitimate identity theft, use a payment card for unauthorized spending, or potentially take over a whole account.

So what lessons are out there? Well, for starters: Why are we still using knowledge-based authentication based on third-party-issued data elements to verify transactions? Government identity numbers such as Social Security numbers, home addresses, and users' date of births are "zombie authenticators," devoid of enterprise-caliber security, yet constantly resurfacing. By their very nature as sensitive data, these antiquated static authenticators are worse than passwords. And yet, despite being compromised multiple times and being available on occasion through public or searchable sources, using personal information for authentication is still a common tactic in 2017. I cringe when merchants use these types of questions to authenticate customers.

Fraudsters maintain active databases to store these elements and anyone with an account on the Dark Web can search for identifying information concerning the intended target. In fact, a neologism already exists for this phenomenon, "credential stuffing." The act of intercepting and using as many authentication elements as possible to construct a target profile and take over an account is an established process, built on archives of already compromised data.

In a world where emerging technologies are transforming protocols and workflows across the entire economy, businesses are missing a valuable opportunity to establish a more rigid authentication process, one that uses dynamic, original, and more sophisticated tactics to validate who  a person is. 

The rise of biometrics in remote and mobile app settings (retina scans, face and voice recognition, fingerprints, etc.), dynamic account-based questions with answers known only to the service provider and customer, and multifactor out-of-band authentication provided via a separate network are just three alternatives that can be embraced in tandem for a smoother authentication experience that simultaneously reduces the potential for account takeover. Would I feel more secure in a world of high-frequency data breaches knowing my financial institution authenticates me with at least two factors? Could this be faster than the present authentication practice of asking multiple questions throughout a contact center session? The answer to both questions is yes.

A formal overhaul of payments authentication is already underway in some regions. As European institutions prepare for PSD2 and its residual impact on digital commerce and cross-border payments, the Strong Consumer Authentication standards within this mandate have created a potential benchmark for secure authentication in the enterprise. With Stratistics MRC estimating that the global multifactor authentication market will grow to $13.59 billion by 2022, we're procuring new security mechanisms that will tap into a range of interchangeable knowledge, possession, and inherence-based identifiers. 

Organizations in the US must follow suit in their network and data protection methods. Establishing proactive monitoring processes and preparing an incident response plan in advance can reduce the flow of sensitive data leaving a business. Taking steps to encrypt the data itself is another means of ensuring that hackers don't have free rein over data, and the well-being of an organization's reputation once they've bypassed peripheral security solutions.

While no one wants to receive a somber letter from their financial institution, or look themselves up on a newly created security webpage to determine the status of their security following a breach, this is the new reality we live in. To sit idly by and continue authenticating with the most consistent static data elements is a lesson of any breach du jour. 

Related Content:

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Seth Ruden is a senior fraud consultant at ACI Worldwide with more than a decade of direct experience in financial services. As a certified fraud examiner and anti-money laundering specialist, Seth has worked with banks, law enforcement, regulators and analysts across the US, ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12420
PUBLISHED: 2019-12-12
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.
CVE-2019-16774
PUBLISHED: 2019-12-12
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
CVE-2018-11805
PUBLISHED: 2019-12-12
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf ...
CVE-2019-5061
PUBLISHED: 2019-12-12
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table att...
CVE-2019-5062
PUBLISHED: 2019-12-12
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w, resulting in a denial of...