Awareness - Passwords, Spell Checkers, and MFA

Awareness - Passwords, Spell Checkers, and MFA

Introduction

We like to make you aware of some of the current security vulnerabilities, what you can do and what anDREa is doing to mitigate the risks.

Passwords & Spell Checkers

Spell checkers offered by browsers, but also apps like Grammarly, pose a serious security risk; these applications are found to capture everything, send and receive everything plain text; including passwords.
Source: Google, Microsoft can get your passwords via web browser's spellcheck


What you can do (highly recommended):
  1. Disable spelling checkers that work on browser pages
    1. Chrome / Edge / Firefox
      1. Go to settings, type in search: Spelling
      2. Disable
  2. Do not use applications like Grammarly in your browser while typing passwords

What anDREa can do:
  1. At this moment, nothing

MFA

MFA, Multi-Factor Authentication seriously improved the security of your data. However, the 'community' is not sitting idle and is currently exploiting what is known as MFA prompt spamming / MFA fatique.

Sources: Microsoft accounts targeted with new MFA-bypassing phishing kit, and MFA prompt spamming/ MFA fatigue – What can you do to prevent/ detect attacks?

What you can do (highly recommended):
  1. Only accept MFAs when the application in front of you is requesting it

What anDREa can do:
  1. To be rolled out very soon:
    1. Adding extra context to the MFA request the following information:
      1. Location, the name of the App
  2. In the 'back pocket'
    1. Require number matching (effective, but not a nice user experience)
  3. To be explored (not even known if it is feasible for myDRE)
    1. Passwordless