Awareness - Passwords, Spell Checkers, and MFA
Introduction
We like to make you aware of some of the current security vulnerabilities, what you can do and what anDREa is doing to mitigate the risks.
Passwords & Spell Checkers
Spell checkers offered by browsers, but also apps like Grammarly, pose a serious security risk; these applications are found to capture everything, send and receive everything plain text; including passwords.
What you can do (highly recommended):
- Disable spelling checkers that work on browser pages
- Chrome / Edge / Firefox
- Go to settings, type in search: Spelling
- Disable
- Do not use applications like Grammarly in your browser while typing passwords
What anDREa can do:
- At this moment, nothing
MFA
MFA, Multi-Factor Authentication seriously improved the security of your data. However, the 'community' is not sitting idle and is currently exploiting what is known as MFA prompt spamming / MFA fatique.
What you can do (highly recommended):
- Only accept MFAs when the application in front of you is requesting it
What anDREa can do:
- To be rolled out very soon:
- Adding extra context to the MFA request the following information:
- Location, the name of the App
- In the 'back pocket'
- Require number matching (effective, but not a nice user experience)
- To be explored (not even known if it is feasible for myDRE)
- Passwordless
Related Articles
Awareness - MFA: number matching, location and additional context
The Microsoft Authenticator app will enforce number matching starting February 27th 2023 in response to MFA fatique attacks. anDREa has already enabled location and additional context, number matching will follow soon. Activation date to be decided, ...
Awareness - MFA: number matching, location and additional context
TL;DR: The Microsoft Authenticator app will enforce number matching starting February 27th 2023 in response to MFA fatigue attacks. anDREa has already enabled location and additional context, number matching will follow soon. Activation date to be ...
Awareness - Malicious code packages in repositories
anDREa B.V. takes information security very seriously. We recently engaged in the ISO 27001 certification process. Moreover, we are subscribed to several security news feeds. As a result, we will post awareness articles from time to time with ...
Awareness - MFA protects but make sure the site is okay
version: 2022-04-14 Introduction MFA is a good way to protect against hackers, but on Tuesday, Microsoft detailed an ongoing large-scale phishing campaign that can hijack user accounts when they're protected with MFA designed to prevent such ...
Awareness - Malicious code packages in repositories
Version: 2022-08-16 Introduction anDREa B.V. takes information security very seriously. We recently engaged in the ISO 27001 certification process. Moreover, we are subscribed to several security news feeds. As a result, we will post awareness ...