Introduction
We like to make you aware of some of the current security vulnerabilities, what you can do and what anDREa is doing to mitigate the risks.
Passwords & Spell Checkers
Spell checkers offered by browsers, but also apps like Grammarly, pose a serious security risk; these applications are found to capture everything, send and receive everything plain text; including passwords.
What you can do (highly recommended):
- Disable spelling checkers that work on browser pages
- Chrome / Edge / Firefox
- Go to settings, type in search: Spelling
- Disable
- Do not use applications like Grammarly in your browser while typing passwords
What anDREa can do:
- At this moment, nothing
MFA
MFA, Multi-Factor Authentication seriously improved the security of your data. However, the 'community' is not sitting idle and is currently exploiting what is known as MFA prompt spamming / MFA fatique.
What you can do (highly recommended):
- Only accept MFAs when the application in front of you is requesting it
What anDREa can do:
- To be rolled out very soon:
- Adding extra context to the MFA request the following information:
- Location, the name of the App
- In the 'back pocket'
- Require number matching (effective, but not a nice user experience)
- To be explored (not even known if it is feasible for myDRE)
- Passwordless