AI
AI

Design Flaw in Microsoft Authenticator Causes MFA Account Overwrites, Locking Users Out

Photo credit: www.csoonline.com

“It seems the solution, or rather a viable workaround, is to manually enter the Secret Key from the Identity Provider into the Authenticator app during its setup phase,” shared a concerned user. “This approach, however, presents challenges in a corporate setting where most end users are not familiar with the complexities of authentication processes, making a random sequence of characters seem quite daunting.”

‘A significant challenge with usability and cybersecurity’

This issue gained traction recently after Australian IT consultant Brett Randall highlighted it on LinkedIn.

In his post, Randall recounted his experience during a recent vendor training session: “While logging into their platform, we encountered a QR code for multi-factor authentication (MFA). Several participants opened the Microsoft Authenticator app, scanned the QR code, and accidentally replaced another application’s TOTP (Time-based One-Time Password) key,” Randall noted.

Source
www.csoonline.com

Related by category

Broadcom-Supported SAN Devices Vulnerable to Code Injection Attacks Due to Critical Fabric OS Flaw

Photo credit: www.csoonline.com Critical Vulnerability Found in Broadcom’s Brocade Fabric...

Cyberattack on berlin.de | CSO Online

Photo credit: www.csoonline.com Cyberangriff auf Berlins Info- und Serviceportal berlin.de Ende...

The Rising Tide of Intrusions: Increased Stolen Credentials and Perimeter Exploits Amid Declining Phishing Attacks

Photo credit: www.csoonline.com The landscape of cybersecurity continues to evolve,...

Latest news

Classic Crepes Suzette with a Vibrant Twist Using This Everyday Ingredient!

Photo credit: www.seriouseats.com Classic Crêpes Suzette with a Colorful Twist Why...

Taylor Swift Appears Youthful in 2015 Snapshot with Ed Sheeran

Photo credit: www.instyle.com Ed Sheeran Shares Throwback Photo of Young...

Online vs. In-Person Purchases: What to Buy Where

Photo credit: www.bustle.com Beyoncé's merchandise during her concert tours tends...

Breaking news