MFA (2FA) is great, but… 😑 Identity theft on tape

https://youtu.be/IdJITWfE1HI Imagine you've rolled out a great thing in your company β€” multi-factor authentication .

https://youtu.be/IdJITWfE1HI

Imagine you've rolled out a great thing in your company β€” multi-factor authentication. You even went so far as to give employees FIDO keys (so-called phishing-resistant MFA β€” in plain English: a FIDO key won't authenticate against a spoofed domain in a phishing email = man-in-the-middle is solved too).

You think you've got everything "locked down" and can sleep easy. The catch is that MFA only protects the sign-in process β€” and here come the COOOOOKIES. After every sign-in, certain artefacts are left on the device (in our case, cookies), and unfortunately those can be stolen. They're there so you don't have to keep signing in over and over.

🀨 OK, where's the problem?

One path can be BYOD devices (private user devices like a home computer). Kids download cracked Photoshops and similar fun, which during installation often also installs a piece of software that steals the cookies.

Forgive me, experts β€” I shot a simplified video showing how it's done by hand without scripts. An attacker would do this on autopilot at lightning speed in the background. The video shows theft of a global admin account = this is one of the reasons you don't work under privileged accounts.

😊 More videos coming

Next time we'll look at what you should definitely block in your Microsoft 365 environment. It's actually allowed by default… and may be even more of a "WTF" than today's video. You won't even need an infected device πŸ™„ β€” just an employee with good intentions trying to automate something or come up with an innovative solution 😳. That's super-popular today, especially anything AI.

πŸ˜‚ All events in this post are fictional. Any resemblance to real companies, events, or people is entirely coincidental.