Why MFA isn’t enough to protect you Person using a mobile device with padlock symbol overlaid


For years we’ve seen security professionals urging developers to secure their applications by implementing Multi-Factor Authentication (MFA) as an extra layer of cybersecurity beyond passwords. But, unfortunately, this has proven to not be enough. According to a study conducted by Sift, account takeover fraud grew by 250% in 2020, despite the addition of MFA.
About the author
André Ferraz is the founder and CEO of Incognia.
Fraudsters have learned quickly how to bypass the most popular MFA methods such as one-time passwords (OTPs), facial recognition and others. In this article, we will discuss the issues related to OTPs and facial recognition as some of the most popular and effective forms of MFA.
The problem with OTPs
The main security issue is that phishing and social engineering attacks, which are the main cause of identity fraud, can lead users to give away their one-time passwords to fraudsters. Fraudsters are able to gain customers’ trust over email, phone, or social media, convincing them to provide their credentials.
Another security issue is that OTPs can be easily intercepted. Fraudsters have learned quickly how to bypass the most popular OTP methods. For example, SMS can be intercepted at scale and the phone number also can be compromised with a SIM swap attack. Consumer emails are also easily compromised, making it not the most secure channel. For example, in 2018 it was revealed that only 10% of users adopted the option of two-factor authentication (2FA) on Gmail.
Another major problem with OTPs is that they create too much friction for the user, impacting the user experience. Arguably, it adds more friction than normal passwords. This added friction ends up leading to customer dropoff and lower retention rates. A recent study showed that less than 2.5% of Twitter users activate OTPs, clearly demonstrating that users chose convenience over security.
The problem with facial recognition
With the introduction in 2017 of the Face ID feature, Apple brought face recognition technology to the forefront for many people. Facial recognition today is commonly used to unlock phones and authenticate users to online services. However, it has also become a target for fraudsters. A person’s face is static data, which means it can never be changed. Once this data is in possession of bad actors, the owner of that data would never be safe using that as proof of identity ever again.
Fraudsters are using data from many sources, including social media, to fool facial recognition systems. More sophisticated attacks are also being developed. A recent paper published by researchers from Israel discusses the development of a neural network capable of generating ‘master’ faces – facial images that are each capable of impersonating multiple IDs. The work suggests that it’s possible to generate such ‘master keys’ for more than 40% of the population using only nine faces synthesized by the StyleGAN Generative Adversarial Network (GAN), via three leading face recognition systems.
How to enhance security in your authentication flow?
Balancing security and user experience is no easy task, but the good news is that there is a lot of innovation in the security industry. In recent years, new technologies have been developed to address the UX vs. security dilemma. They do this by providing passive authentication techniques that work silently in the background.
An example is device fingerprinting technology that can silently recognize devices based on their unique attributes and determine if they should be trusted. Most apps and websites already employ this technology. Additionally, another type of passive authentication method was introduced, called behavioral biometrics. Behavioral biometrics identifies authorized users based on their gestures with the mouse or touchscreen, how they type, and how they hold their phone. Unfortunately, most behavioral biometrics solutions require time to train and achieve high performance, and the integration process can be complex.
Most recently, with the growing relevance of mobile as the main online channel, location behavior data from on-device sensors is now being leveraged to identify when a user is accessing or transacting from a trusted location. In a recent study conducted by Incognia, it was found that 90% of the legitimate logins and 95% of the legitimate high-risk transactions happen from a trusted location, which is a place that is part of the user’s regular routine such as their home, office or favorite restaurant. The greatest advantage of leveraging location behavior is that it is highly effective at assessing risk, with a failure rate of 1 in 100,000,000 transactions, and it doesn’t require any user action, delivering the best possible user experience.
There is no silver bullet in the security space, so developers should go for a layered approach. Ideally, apps would leverage passive authentication for the vast majority of low-risk scenarios and introduce the friction of MFA only when high-risk is identified. That way, apps can provide a frictionless authentication experience to legitimate customers but keep the fraudsters away.
For years we’ve seen security professionals urging developers to secure their applications by implementing Multi-Factor Authentication (MFA) as an extra layer of cybersecurity beyond passwords. But, unfortunately, this has proven to not be enough. According to a study conducted by Sift, account takeover fraud grew by 250% in 2020, despite…
Recent Posts
- Elon Musk says Grok 2 is going open source as he rolls out Grok 3 for Premium+ X subscribers only
- FTC Chair praises Justice Thomas as ‘the most important judge of the last 100 years’ for Black History Month
- HP acquires Humane AI assets and the AI pin will suffer a humane death
- HP acquires Humane AI assets and the AI pin may suffer a humane death
- HP acquires Humane Ai and gives the AI pin a humane death
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010