More

    Windows Entra IDs can be bypassed worryingly easily – here’s what we know




    • Experts warn FIDO is not supported on certain clients when accessing Entra ID
    • This triggers a fallback login mechanism that can be picked up
    • Mitigations should be put in place, researchers say

    FIDO-based authenticator apps are considered one of the strongest practical defenses against phishing and credential theft, but judging by Proofpoint’s latest research, it is not without its weaknesses.

    The company’s researchers say they have found a way to force a target to abandon FIDO-based authentication for a weaker login method which can be picked up in transit.

    https://cdn.mos.cms.futurecdn.net/hCciw9cBypDVf32HBmiya.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img