<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FBI warns of MFA in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/FBI-warns-of-MFA/m-p/28847#M3544</link>
    <description>&lt;P&gt;SMS OTP used to be classed in the UK public sector as a non accreditable form of 2FA, but if you take the stance of it being more secure than username/password, then it's obviously worth implementing.&amp;nbsp; If we're going to assume that an attack can compromise or steal the second factor then no MFA scheme is entirely secure.&amp;nbsp; It's about risk reduction and risk appetite and that's context dependent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Oct 2019 10:51:06 GMT</pubDate>
    <dc:creator>Steve-Wilme</dc:creator>
    <dc:date>2019-10-10T10:51:06Z</dc:date>
    <item>
      <title>FBI warns of MFA</title>
      <link>https://community.isc2.org/t5/Industry-News/FBI-warns-of-MFA/m-p/28819#M3542</link>
      <description>&lt;P&gt;The FBI has sent out a warning that the &lt;A href="https://www.zdnet.com/article/fbi-warns-about-attacks-that-bypass-multi-factor-authentication-mfa/" target="_blank" rel="noopener"&gt;bad guys are attacking multi-factor authentication&lt;/A&gt; (MFA).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In reality, when you read the details of the attacks, it boils down to SIM swapping and some other implementation attacks, most of them fairly rare.&amp;nbsp; As usual, the price of security is eternal vigilance, and when you try to take the easy route, you usually become a target ...&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 18:30:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/FBI-warns-of-MFA/m-p/28819#M3542</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-10-09T18:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: FBI warns of MFA</title>
      <link>https://community.isc2.org/t5/Industry-News/FBI-warns-of-MFA/m-p/28831#M3543</link>
      <description>&lt;P&gt;Here is an interesting &lt;A href="https://techcommunity.microsoft.com/t5/Azure-Active-Directory-Identity/All-your-creds-are-belong-to-us/ba-p/855124" target="_blank" rel="noopener"&gt;comparison&lt;/A&gt; of various authenticators.&amp;nbsp; The biggest takeaway is "&lt;SPAN&gt;You should definitely turn on MFA now&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;– and anything is &amp;gt;99.9% better than nothing.&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 20:24:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/FBI-warns-of-MFA/m-p/28831#M3543</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2019-10-09T20:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: FBI warns of MFA</title>
      <link>https://community.isc2.org/t5/Industry-News/FBI-warns-of-MFA/m-p/28847#M3544</link>
      <description>&lt;P&gt;SMS OTP used to be classed in the UK public sector as a non accreditable form of 2FA, but if you take the stance of it being more secure than username/password, then it's obviously worth implementing.&amp;nbsp; If we're going to assume that an attack can compromise or steal the second factor then no MFA scheme is entirely secure.&amp;nbsp; It's about risk reduction and risk appetite and that's context dependent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 10:51:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/FBI-warns-of-MFA/m-p/28847#M3544</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-10-10T10:51:06Z</dc:date>
    </item>
  </channel>
</rss>

