A passwordless future: Why not all MFA really protects you

Although any form of MFA offers better security than a password alone, not all MFA is created equal.

Simple or outdated forms of MFA, such as SMS, mobile authentication, email ‘magic links’ and one-time passwords (OTP), can be easily circumvented by malicious actors.

These methods rely on shared secrets that are vulnerable to account takeovers through phishing, social engineering, and man-in-the-middle (MITM) attacks, with an attack penetration rate of 10–24%.

66% of organisations say they are testing, have already implemented, or are planning to implement passwordless authentication as they move away from problematic passwords and phishing-prone MFA*.

To ensure a secure transition to passwordless authentication, this white paper explains key implementation factors to consider when moving to passwordless authentication using passkeys to ensure strong security throughout the authentication cycle.

*Source: S&P Global Market Intelligence, With Security Breaches Mounting, Now Is the Time To Move From Legacy MFA to Modern, Phishing-Resistant MFA, 2023

If you are interested, our Yubico-Team here for you.

 

Back to Yubico News.

Our Yubico team will be happy to assist you with your sales enquiries, pre-sales issues or planned marketing activities.