MFA (2FA) is great, butβ¦ π‘ Identity theft on tape
https://youtu.be/IdJITWfE1HI Imagine you've rolled out a great thing in your company β multi-factor authentication .
Imagine you've rolled out a great thing in your company β multi-factor authentication. You even went so far as to give employees FIDO keys (so-called phishing-resistant MFA β in plain English: a FIDO key won't authenticate against a spoofed domain in a phishing email = man-in-the-middle is solved too).
You think you've got everything "locked down" and can sleep easy. The catch is that MFA only protects the sign-in process β and here come the COOOOOKIES. After every sign-in, certain artefacts are left on the device (in our case, cookies), and unfortunately those can be stolen. They're there so you don't have to keep signing in over and over.
π€¨ OK, where's the problem?
One path can be BYOD devices (private user devices like a home computer). Kids download cracked Photoshops and similar fun, which during installation often also installs a piece of software that steals the cookies.
Forgive me, experts β I shot a simplified video showing how it's done by hand without scripts. An attacker would do this on autopilot at lightning speed in the background. The video shows theft of a global admin account = this is one of the reasons you don't work under privileged accounts.
π More videos coming
Next time we'll look at what you should definitely block in your Microsoft 365 environment. It's actually allowed by defaultβ¦ and may be even more of a "WTF" than today's video. You won't even need an infected device π β just an employee with good intentions trying to automate something or come up with an innovative solution π³. That's super-popular today, especially anything AI.
π All events in this post are fictional. Any resemblance to real companies, events, or people is entirely coincidental.