<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIM Based Authentication to reduce Phishing attacks in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/SIM-Based-Authentication-to-reduce-Phishing-attacks/m-p/51205#M3520</link>
    <description>&lt;P&gt;General advice I hear is "&lt;SPAN&gt;SMS and call-based MFA [are] the least secure of the MFA methods available today" [&lt;A href="https://www.zdnet.com/article/microsoft-urges-users-to-stop-using-phone-based-multi-factor-authentication/" target="_blank" rel="noopener"&gt;cite&lt;/A&gt;].&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;It is good to see that the article's subject is attempting to address SMS weaknesses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My personal favorite MFA defense at the moment is the "&lt;A href="https://m365admin.handsontek.net/microsoft-authenticator-code-matching-for-mfa-notifications/" target="_blank" rel="noopener"&gt;number matching&lt;/A&gt;" mechanism.&amp;nbsp;&lt;SPAN&gt;That said, &lt;STRONG&gt;Even the worst MFA is substantially better than NO MFA&lt;/STRONG&gt;, so I will gladly leverage whatever the IdP offers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Plus, we should be striving to minimize user-disruption with technologies such as cert-auth, SSO, and face-id, reserving traditional MFA for high-risk activities such as device registration and password resets.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 26 May 2022 04:23:06 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2022-05-26T04:23:06Z</dc:date>
    <item>
      <title>SIM Based Authentication to reduce Phishing attacks</title>
      <link>https://community.isc2.org/t5/Tech-Talk/SIM-Based-Authentication-to-reduce-Phishing-attacks/m-p/51195#M3518</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This looks like an interesting idea for reducing phishing attacks against mobile devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you think?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://thehackernews.com/2022/05/sim-based-authentication-aims-to.html" target="_blank"&gt;https://thehackernews.com/2022/05/sim-based-authentication-aims-to.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:11:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/SIM-Based-Authentication-to-reduce-Phishing-attacks/m-p/51195#M3518</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T10:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: SIM Based Authentication to reduce Phishing attacks</title>
      <link>https://community.isc2.org/t5/Tech-Talk/SIM-Based-Authentication-to-reduce-Phishing-attacks/m-p/51205#M3520</link>
      <description>&lt;P&gt;General advice I hear is "&lt;SPAN&gt;SMS and call-based MFA [are] the least secure of the MFA methods available today" [&lt;A href="https://www.zdnet.com/article/microsoft-urges-users-to-stop-using-phone-based-multi-factor-authentication/" target="_blank" rel="noopener"&gt;cite&lt;/A&gt;].&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;It is good to see that the article's subject is attempting to address SMS weaknesses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My personal favorite MFA defense at the moment is the "&lt;A href="https://m365admin.handsontek.net/microsoft-authenticator-code-matching-for-mfa-notifications/" target="_blank" rel="noopener"&gt;number matching&lt;/A&gt;" mechanism.&amp;nbsp;&lt;SPAN&gt;That said, &lt;STRONG&gt;Even the worst MFA is substantially better than NO MFA&lt;/STRONG&gt;, so I will gladly leverage whatever the IdP offers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Plus, we should be striving to minimize user-disruption with technologies such as cert-auth, SSO, and face-id, reserving traditional MFA for high-risk activities such as device registration and password resets.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 04:23:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/SIM-Based-Authentication-to-reduce-Phishing-attacks/m-p/51205#M3520</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2022-05-26T04:23:06Z</dc:date>
    </item>
  </channel>
</rss>

