4.8 • 1K Ratings
🗓️ 13 September 2022
⏱️ 26 minutes
🧾️ Download transcript
Multi-Factor Authentication (MFA) is usually considered a better solution for authentication than just using passwords. But Roger Grimes, a veteran security professional, and a Data-Driven Defense Evangelist claims that the sense of security current MFA solutions provides us - is false.
Click on a timestamp to play from that location
0:00.0 | I can hack the average MFA solution at least five ways and most of them 10-11 ways at least. |
0:17.0 | Hi and welcome to Sabirism's malicious life besides. I'm Ram Levy. If you've been following cyber security news for the past, I don't know, 20 years? I don't need to tell you that passwords are not a great |
0:36.8 | solution for authentication. Most people choose weak passwords or reuse their passwords across different services and even if you |
0:46.2 | follow all the best practices your passwords might still be compromised by a data breach. |
0:52.9 | The basic problem with passwords is that they are but a single piece of evidence that you are who |
0:59.1 | you say you are. |
1:00.8 | Evidence based on what you know. That is, the assumption is that you are the only |
1:05.7 | one who knows your password. We used easy to guess or compromise passwords all |
1:11.5 | negate this basic assumption. |
1:15.0 | Multifactor authentication tries to solve this problem by providing the user with other ways |
1:21.0 | to prove he or she is indeed who they say they are. with something they have like a USB security token for |
1:28.7 | example something they are something they are like a unique fingerprint or somewhere they are, like a unique fingerprint, or somewhere they are, like using a GPS to verify your |
1:37.1 | location. |
1:38.3 | Combining two or more such authentication factors greatly increases the likelihood that you are indeed who you claim to be, |
1:46.3 | which is why MFA has become so popular. |
1:49.7 | But this episode's guest says that this sense of security is false. |
1:56.0 | That many, if not most, current implementations of multi-factor authentication, |
2:01.0 | and in particular SMS-based authentication are not nearly as |
2:05.8 | secure as we'd like to think they are. |
2:08.7 | Roger Grimes has been fighting malware and malicious hackers since 1987. |
2:14.0 | It was Microsoft's principal security architect for 11 years |
2:18.0 | and has written no less than 13 books and 1100 articles on computer security. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from Malicious Life, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of Malicious Life and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.