{"id":1133,"date":"2022-01-28T14:50:00","date_gmt":"2022-01-28T21:50:00","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/?p=1133"},"modified":"2022-01-27T21:36:19","modified_gmt":"2022-01-28T04:36:19","slug":"2fa-is-no-longer-secure-enough","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/01\/28\/2fa-is-no-longer-secure-enough\/","title":{"rendered":"2FA is no longer secure enough."},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">It has been a recent uprising during the past couple of years that companies and services have encouraged to start rolling out two-factor authentication modalities to its users whether it be in the form of a text-message, email, through an authentication app or via other means.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, a recent security breach fell upon the hands on a Maltese crypto-coin broker <em>Foris DAX MT Ltd,<\/em> or known more commonly as Crypto.com released a <a href=\"https:\/\/crypto.com\/product-news\/crypto-com-security-report-next-steps\" data-type=\"URL\" data-id=\"https:\/\/crypto.com\/product-news\/crypto-com-security-report-next-steps\">security report<\/a> <sub>[1] <\/sub> which outlined the biggest culprit which lost them a total of 4,836.26 Etherium and 443.93 Bitcoin, $66,200 USD in value in other smaller cryptocurrencies; totalling up to nearly $35,000,000 dollars. The culprit was 2FA tokens not being triggered.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"so-what-happened\">So what happened?<\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-src=\"https:\/\/imageio.forbes.com\/specials-images\/imageserve\/61e980d4e1dfb2c643f40200\/Cryptocurrency-Companies-Photo-Illustrations\/960x0.jpg?fit=bounds&amp;format=jpg&amp;width=960\" alt=\"Cryptocurrency Companies Photo Illustrations\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" \/><figcaption>crypto.com one-time passwords (nurtphoto via getty images)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This largest finger to point to is Crypto.com themselves due to a misconfiguration of their one-time password approach, which were six-digit codes provided to a user via a text or by a multi-factor authentication application states <em>Zilvinas Bareisis<\/em> from an interview with <em><a href=\"https:\/\/www.americanbanker.com\/news\/crypto-com-hack-exposes-shortcomings-of-multifactor-authentication\">American Banker<\/a><\/em> [2]. Bareisis hypothesizes that Crypto.com mistakenly allowed users to authorize transactions without needing this one-time code or that hackers through a more invasive approach, intercepted these one-time passwords; affecting 483 users. Although resolved, Crypto.com and its users were impacted albeit the affected accounts being restored with Crypto&#8217;s own funds.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-did-they-fix-this\">How did they fix this?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Supposedly the company&#8217;s risk monitoring systems were able to detect the issue in which they say &#8220;triggered an immediate response from multiple teams to assess the impact,&#8221; resulting in a 14 hour downtime to precisely locate and fix the issue. Due to this issue, Crypto.com decided to implement a new 2FA infrastructure, which in short means users will now have the chance to enroll in an insurance program to cover up to $250,000 in losses but only if they enable a <strong>multi-factor<\/strong> authentication. Also, all current users must-reconfigure their accounts in compliance to this new protocol. On the company side, they are fast-forwarding their transition past 2FA as they &#8220;will be releasing additional end-user security features as we move away from 2-Factor Authentication and to true Multi-Factor Authentication (MFA)&#8221; <sub>[1]<\/sub>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-is-this-a-big-deal\">Why is this a big deal?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As a huge player in the cryptocurrency game with crypto coins being a nearly untraceable and non-reversible, having their security breach due to two-factor authentication issues sheds a new look to the transition of having more options to secure your own account. As an avid user of password managers (Bitwarden in my case) I believe that with the rise of database breaches and data being worth more than oil, it is absolutely mandatory for user sensitive data to be protected at a higher cost, even if the minimum requirement is simply a two-factor authentication. Passwords have never been enough for the past couple of years and two-factor authentication is starting to show weaknesses that can cause catastrophic damages to assets, users and company reputation. The ability to layer on an extra layer of protection greatly reduces the risk of even the slightest system error, as an intruder would have to identify and try to bypass a multitude of unique authentication methods  which could range from sms + a physical form (yubikey), sms + email, email + physical form + security questions, etc or even more than three at the same time. The importance of security is more prevalent than ever now and services should start standardizing giving users the ability to protect themselves which as a byproduct protects the companies image as well. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"references\">References:<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">[1] <a href=\"https:\/\/crypto.com\/product-news\/crypto-com-security-report-next-steps\">Crypto.com Security Report &amp; Next Steps<\/a> &#8211; Jan 20, 2022 <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[2] <a href=\"https:\/\/www.americanbanker.com\/news\/crypto-com-hack-exposes-shortcomings-of-multifactor-authentication\">Crypto.com hack exposes shortcomings of multifactor authentication | American Banker<\/a> &#8211; Jan 26, 2022<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[3] <a href=\"https:\/\/nakedsecurity.sophos.com\/2022\/01\/21\/cryptocoin-broker-crypto-com-says-2fa-bypass-led-to-35m-theft\/\">Cryptocoin broker Crypto.com says 2FA bypass led to $35m theft \u2013 Naked Security (sophos.com)<\/a> &#8211; Jan 21, 2022<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It has been a recent uprising during the past couple of years that companies and services have encouraged to start rolling out two-factor authentication modalities to its users whether it be in the form of a text-message, email, through an authentication app or via other means. However, a recent security breach fell upon the hands &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/01\/28\/2fa-is-no-longer-secure-enough\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;2FA is no longer secure enough.&#8221;<\/span><\/a><\/p>\n","protected":false},"author":288,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-1133","post","type-post","status-publish","format-standard","hentry","category-cpsc-329-602-w22","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Duc Nguyen","author_link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/author\/duc-nguyen\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/1133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/users\/288"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/comments?post=1133"}],"version-history":[{"count":4,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/1133\/revisions"}],"predecessor-version":[{"id":1204,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/1133\/revisions\/1204"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/media?parent=1133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/categories?post=1133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/tags?post=1133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}