<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>security on SpartanAuth Blog</title>
    <link>https://blog.spartanauth.com/tags/security/</link>
    <description>SpartanAuth Blog (security)</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 17 May 2022 15:46:07 -0600</lastBuildDate>
    
    <atom:link href="https://blog.spartanauth.com/tags/security/index.xml" rel="self" type="application/rss+xml" />
    
    
    <item>
      <title>SMS OTP</title>
      <link>https://blog.spartanauth.com/posts/sms-otp/</link>
      <pubDate>Tue, 17 May 2022 15:46:07 -0600</pubDate>
      
      <guid>https://blog.spartanauth.com/posts/sms-otp/</guid>
      <description>&lt;p&gt;Have you ever switched phone providers? Maybe you walked into a store, found that shiny new phone you&amp;rsquo;ve always wanted (or just learned that you always wanted). The store employees are super happy with your choice. They get your information, you give them your phone number, and the next thing you know you have a new phone and a new provider. Easy, right?&lt;/p&gt;
&lt;p&gt;Now imagine someone else — who is not you — decides they want a new phone too. Only they want access to some of your accounts. They pretend they are you. They tell the store your phone number. The store activates &lt;em&gt;your&lt;/em&gt; phone number on &lt;em&gt;their&lt;/em&gt; device. They can now receive text messages intended for you. That trick is called &lt;strong&gt;SIM swapping&lt;/strong&gt;. There are other ways attackers get SMS messages too: forwarding numbers, account-port abuse, or social engineering someone at the carrier.&lt;/p&gt;
&lt;div class=&#34;stat-row&#34;&gt;

&lt;figure class=&#34;stat-card stat-card--compact&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;SIM swap&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Your number, their device — SMS codes included&lt;/figcaption&gt;&lt;/figure&gt;

&lt;figure class=&#34;stat-card stat-card--compact&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;Port / forward&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Other ways attackers redirect texts&lt;/figcaption&gt;&lt;/figure&gt;


&lt;/div&gt;

&lt;p&gt;All this to say: SMS and phone numbers are weak channels for security-sensitive messages. For something so easy to redirect, it is surprising how often we still use them as a &amp;ldquo;second factor&amp;rdquo; protecting real accounts. Microsoft has even &lt;a href=&#34;https://www.thurrott.com/cloud/243821/microsoft-stop-using-sms-for-mfa#:~:text=SMS%2Dbased%20authentication%2C%20he,an%20authentication%20attempt%20fails.&#34;&gt;suggested&lt;/a&gt; that SMS-based MFA is a bad idea.&lt;/p&gt;
&lt;figure class=&#34;stat-card stat-card--compact&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;Avoid SMS MFA&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Even major vendors have warned against SMS as a second factor&lt;/figcaption&gt;&lt;div class=&#34;stat-card-source&#34;&gt;&lt;a href=&#34;https://www.thurrott.com/cloud/243821/microsoft-stop-using-sms-for-mfa&#34; rel=&#34;noopener&#34;&gt;Microsoft (via Thurrott)&lt;/a&gt;&lt;/div&gt;&lt;/figure&gt;

&lt;p&gt;That is why &lt;strong&gt;I am not implementing SMS 2FA in &lt;a href=&#34;https://www.spartanauth.com&#34;&gt;SpartanAuth&lt;/a&gt;&lt;/strong&gt;. I would rather push people toward stronger factors and clearer UX than paper over account recovery with a channel attackers already know how to steal. SpartanAuth focuses on better options instead.&lt;/p&gt;
&lt;figure class=&#34;stat-card stat-card--compact&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;No SMS 2FA&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;By design in SpartanAuth — stronger factors instead&lt;/figcaption&gt;&lt;/figure&gt;

&lt;p&gt;If you have feature requests or opinions on which factors matter most in practice, I want to hear them. Reach me at &lt;a href=&#34;mailto:feedback@spartanauth.com&#34;&gt;feedback@spartanauth.com&lt;/a&gt;.&lt;/p&gt;
&lt;aside class=&#34;waitlist-cta&#34; aria-label=&#34;SpartanAuth updates&#34;&gt;
  &lt;p class=&#34;waitlist-cta-kicker&#34;&gt;Stay in the loop&lt;/p&gt;
  &lt;p class=&#34;waitlist-cta-text&#34;&gt;
    Get occasional notes from me on authentication and SpartanAuth — plus early access as new things ship.
  &lt;/p&gt;
  &lt;p class=&#34;waitlist-cta-action&#34;&gt;
    &lt;a class=&#34;waitlist-cta-button&#34; href=&#34;https://lc.spartanauth.com/q/waitlist-sa/start&#34; rel=&#34;noopener&#34;&gt;Get updates&lt;/a&gt;
  &lt;/p&gt;
  &lt;p class=&#34;waitlist-cta-note&#34;&gt;Low volume. No spam. Unsubscribe anytime.&lt;/p&gt;
&lt;/aside&gt;</description>
    </item>
    
    <item>
      <title>Cost of Passwords</title>
      <link>https://blog.spartanauth.com/posts/cost-of-passwords/</link>
      <pubDate>Tue, 17 May 2022 13:29:04 -0600</pubDate>
      
      <guid>https://blog.spartanauth.com/posts/cost-of-passwords/</guid>
      <description>&lt;p&gt;I keep coming back to a blunt fact: passwords are expensive. Not just annoying — expensive in support time, abandoned checkouts, and breach cleanup.&lt;/p&gt;
&lt;p&gt;It has been observed that many companies&amp;rsquo; support teams are overloaded with password reset calls. &lt;a href=&#34;https://www.techtarget.com/searchenterprisedesktop/tip/Resetting-passwords-in-the-enterprise-without-the-help-desk#:~:text=Forrester%20Research%20estimates%20that%20the%20average%20cost%20of%20a%20single%20password%20reset%20done%20by%20help%20desk%20is%20about%20%2470%2C%20while%20Gartner%20estimates%20that%2020%25%20to%2050%25%20of%20all%20help%20desk%20calls%20are%20for%20password%20resets.&#34;&gt;According to research from Forrester&lt;/a&gt;, the average cost for a single password reset is about $70. Another report by Gartner estimates that 20% to 50% of all help desk calls are for password resets.&lt;/p&gt;
&lt;div class=&#34;stat-row&#34;&gt;

&lt;figure class=&#34;stat-card&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;$70&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Average cost of one help-desk password reset&lt;/figcaption&gt;&lt;div class=&#34;stat-card-source&#34;&gt;&lt;a href=&#34;https://www.techtarget.com/searchenterprisedesktop/tip/Resetting-passwords-in-the-enterprise-without-the-help-desk&#34; rel=&#34;noopener&#34;&gt;Forrester&lt;/a&gt;&lt;/div&gt;&lt;/figure&gt;

&lt;figure class=&#34;stat-card&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;20–50%&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Of help desk calls are password resets&lt;/figcaption&gt;&lt;div class=&#34;stat-card-source&#34;&gt;&lt;a href=&#34;https://www.techtarget.com/searchenterprisedesktop/tip/Resetting-passwords-in-the-enterprise-without-the-help-desk&#34; rel=&#34;noopener&#34;&gt;Gartner&lt;/a&gt;&lt;/div&gt;&lt;/figure&gt;


&lt;/div&gt;

&lt;p&gt;On top of all this, according to a &lt;a href=&#34;https://www.ibm.com/security/data-breach&#34;&gt;report from IBM&lt;/a&gt;, 20% of all breaches came from compromised credentials.&lt;/p&gt;
&lt;p&gt;Global average total cost of a data breach is $4.24m, but in the United States that average cost more than doubles to $9.05m. I highly recommend reading that report. It has tons more information about the cost of data breaches.&lt;/p&gt;
&lt;div class=&#34;stat-row&#34;&gt;

&lt;figure class=&#34;stat-card&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;20%&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Of breaches involved compromised credentials&lt;/figcaption&gt;&lt;div class=&#34;stat-card-source&#34;&gt;&lt;a href=&#34;https://www.ibm.com/security/data-breach&#34; rel=&#34;noopener&#34;&gt;IBM&lt;/a&gt;&lt;/div&gt;&lt;/figure&gt;

&lt;figure class=&#34;stat-card&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;$4.24M&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Global average cost of a data breach&lt;/figcaption&gt;&lt;div class=&#34;stat-card-source&#34;&gt;&lt;a href=&#34;https://www.ibm.com/security/data-breach&#34; rel=&#34;noopener&#34;&gt;IBM&lt;/a&gt;&lt;/div&gt;&lt;/figure&gt;

&lt;figure class=&#34;stat-card&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;$9.05M&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Average breach cost in the United States&lt;/figcaption&gt;&lt;div class=&#34;stat-card-source&#34;&gt;&lt;a href=&#34;https://www.ibm.com/security/data-breach&#34; rel=&#34;noopener&#34;&gt;IBM&lt;/a&gt;&lt;/div&gt;&lt;/figure&gt;


&lt;/div&gt;

&lt;p&gt;Needless to say, passwords are expensive.&lt;/p&gt;
&lt;p&gt;So, what do we do about it?&lt;/p&gt;
&lt;p&gt;There are several technologies that attempt to mitigate the costs and risks of passwords. These include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://fidoalliance.org/&#34;&gt;FIDO&lt;/a&gt; - FIDO is a standard that allows users to authenticate without a password. It uses private/public key cryptography to authenticate users.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.w3.org/TR/webauthn/&#34;&gt;WebAuthn&lt;/a&gt; - WebAuthn is a standard that allows users to authenticate without a password on webpages. Also, it is built on top of FIDO.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Multi-factor_authentication&#34;&gt;MFA&lt;/a&gt; - Multi-factor Authentication incorporates several technologies (including some on this list) and techniques such as time-based tokens or biometrics.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/One-time_password&#34;&gt;OTP&lt;/a&gt; - OTP is a standard that sends users a one time use code through a known channel such as email or on a mobile app. See &lt;a href=&#34;https://blog.spartanauth.com/posts/sms-otp/&#34;&gt;this blog post&lt;/a&gt; on why SMS is not a secure channel for OTP.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Time-based_One-time_Password&#34;&gt;TOTP&lt;/a&gt; - TOTP is a standard where an authenticator app stores a shared seed/secret that will generate codes based on the time. The service provider can compare the code sent by the user to verify they had access to the authenticator app.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Biometrics&#34;&gt;Biometrics&lt;/a&gt; - Biometrics allows users to authenticate with something like a fingerprint or face unlock — usually as a local gate to stronger credentials, not as a shared secret by itself.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Hardware_security&#34;&gt;Hardware&lt;/a&gt; - Hardware security allows users to authenticate with a device such as a security key or a smartphone. Some FIDO implementations use hardware to protect the crypto keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All of these approaches seem promising, but there are still a few things to consider. First, the cost of adopting them is not as low as the slide decks imply. Implementing each one well usually means having at least some domain expertise on the team — or paying a large identity provider a lot of money and still doing non-trivial integration work. Second, if the user experience is not planned carefully, people will not understand how to manage their own authentication. When friction goes up, people avoid the secure path. For example, &lt;a href=&#34;https://fidoalliance.org/new-research-reveals-consumer-frustrations-with-online-retail/&#34;&gt;58% in the U.S. have abandoned purchases due to the difficulty of managing passwords&lt;/a&gt;.&lt;/p&gt;
&lt;figure class=&#34;stat-card&#34;&gt;
  &lt;div class=&#34;stat-card-value&#34;&gt;58%&lt;/div&gt;
  &lt;figcaption class=&#34;stat-card-label&#34;&gt;Of U.S. consumers have abandoned a purchase because of password friction&lt;/figcaption&gt;&lt;div class=&#34;stat-card-source&#34;&gt;&lt;a href=&#34;https://fidoalliance.org/new-research-reveals-consumer-frustrations-with-online-retail/&#34; rel=&#34;noopener&#34;&gt;FIDO Alliance&lt;/a&gt;&lt;/div&gt;&lt;/figure&gt;

&lt;p&gt;That tension — better security that people will actually use — is a big part of why I am building &lt;a href=&#34;https://www.spartanauth.com&#34;&gt;SpartanAuth&lt;/a&gt;. I want the stronger options on this list to be easier to integrate into real web and mobile apps without turning auth into a multi-quarter science project. I use SpartanAuth in several of my own applications.&lt;/p&gt;
&lt;p&gt;If you are wrestling with the same password costs, I hope these posts help — and I hope you will take a look at what I am shipping.&lt;/p&gt;
&lt;aside class=&#34;waitlist-cta&#34; aria-label=&#34;SpartanAuth updates&#34;&gt;
  &lt;p class=&#34;waitlist-cta-kicker&#34;&gt;Stay in the loop&lt;/p&gt;
  &lt;p class=&#34;waitlist-cta-text&#34;&gt;
    Get occasional notes from me on authentication and SpartanAuth — plus early access as new things ship.
  &lt;/p&gt;
  &lt;p class=&#34;waitlist-cta-action&#34;&gt;
    &lt;a class=&#34;waitlist-cta-button&#34; href=&#34;https://lc.spartanauth.com/q/waitlist-sa/start&#34; rel=&#34;noopener&#34;&gt;Get updates&lt;/a&gt;
  &lt;/p&gt;
  &lt;p class=&#34;waitlist-cta-note&#34;&gt;Low volume. No spam. Unsubscribe anytime.&lt;/p&gt;
&lt;/aside&gt;</description>
    </item>
    
  </channel>
</rss>
