News: 1667842211

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft hits the switch on password-free smartphone authentication

(2022/11/07)


Microsoft is rolling out another way for smartphone and tablet users to protect themselves from phishing attacks as post-pandemic hybrid work pulls more and more workers under bring-your-own-device (BYOD) policies.

By so doing, of course, it also ties up the security loose ends for businesses, who find BYOD "convenient" ( cough , cheap, cough ) but insecure.

At its Ignite 2022 event last month, Microsoft announced general availability of Azure Active Director (AD) certificate-based authentication (CBA), addressing a component the Biden Administration's [1]executive order last year to strengthen the US's cybersecurity.

[2]

Microsoft is now offering a public preview of Azure AD CBA on devices running Apple's iOS and Android that uses certificates on Yubico's YubiKey hardware security key.

[3]

[4]

The authentication method is based on certificates rather than passwords. Microsoft, along with others including Apple and Google, is pushing for [5]passwordless authentication – and aims to fend off phishing [6]attacks designed to get around multifactor authentication (MFA).

Vimala Ranganathan, product manager for Microsoft Entra, [7]explained that the preview will give mobile device users a login method that supports Federal Information Processing Standards (FIPS) for anti-phishing MFA.

[8]

"On mobile, while customers can provision user certificates on their personal mobile device to be used for authentication, this is primarily feasible for managed mobile devices," Ranganathan said. "But this new public preview unlocks support for BYOD. Customers can now provision certificates on a hardware security key which can then be used for authentication with Azure AD on iOS and Android devices."

iOS device users will have to register for the Yubico Authenticator app to copy YubiKey's public certificate into the iOS keychain and then select the YubiKey certificate to sign in and enter the PIN code.

[9]To cut off all nearby phones with these Chinese chips, this is the bug to exploit

[10]We can't believe people use browsers to manage their passwords, says maker of password management tools

[11]Microsoft lures SMBs to Cloudy PCs by connecting them to Xbox accounts

[12]We were already secure enough for mass remote working before COVID-19, boast IT pros

Android devices enabled by the latest Microsoft Authentication Library (MSAL) won't need the YubiKey Authenticator app. Instead, users can plug in their YubiKey through the USB, initiate Azure AD CBA and pick the certificate from YubiKey. From there they enter the PIN to get authenticated into the app.

The new capability comes as the adoption of BYOD is on the rise, wrote Alex Weinert, vice president and director of identity security at Microsoft. The BYOD space is expected to grow an average of 15.1 percent a year, [13]hitting $485.5 billion by 2025, says market research firm IndustryArc. ®

Get our [14]Tech Resources



[1] https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y2mOCaeJug81Npca5NUS6QAAABM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2mOCaeJug81Npca5NUS6QAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2mOCaeJug81Npca5NUS6QAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/05/05/microsoft-apple-google-fido/

[6] https://www.theregister.com/2022/11/03/mfa_fatigue_enterprise_threat/

[7] https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/azure-ad-certificate-based-authentication-cba-on-mobile/ba-p/2365672

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2mOCaeJug81Npca5NUS6QAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/06/03/uisoc-chip-flaw-check-point/

[10] https://www.theregister.com/2021/07/30/infosec_risky_behaviours_study/

[11] https://www.theregister.com/2022/07/20/windows_365_cloud_pc_upgrades/

[12] https://www.theregister.com/2020/06/22/sectigo_security_survey/

[13] https://www.industryarc.com/Research/Bring-Your-Own-Device-Market-Research-503776

[14] https://whitepapers.theregister.com/



Every time I read CBA...

ICam

I think "Can't Be Arsed" in my head.

More Explanation Needed (...for this confused old f*rt).....

Anonymous Coward

Quote: "...protect themselves from phishing attacks..."

Please explain!!! Phishing attacks only work if an end user clicks a button or connects to a phony web address.

How does a certificate on a personal device "protect" anyone from inbound phishing emails or other inbound malware?

Re: More Explanation Needed (...for this confused old f*rt).....

MatthewSt

Because the majority of phishing attacks convince you to enter your credentials into a site that then goes and makes use of them to spam contacts, exfiltrate data etc

Certificate based has 2 benefits

1) The certificate can be configured to be used on particular websites only (so you're no longer relying on the user noticing a dodgy URL)

2) The private key is never sent to the server, so they can't pretend to be you

Re: More Explanation Needed (...for this confused old f*rt).....

Mayday

Now all we need to do is ensure that users only have “good” certificates installed, don’t install dodgy ones and don’t “click here to read this dodgy site anyway”

Re: More Explanation Needed (...for this confused old f*rt).....

Anonymous Coward

Makes more sense if could assign blame.

None of this "it wasn't me guv"

So... It's a virtual SmartCard then?

J. Cook

Because Depending on the Yubikey one buys (notably the $49 USD one), and with some mucking around with an On-prem AD, you can use the hardware Yubikeys as smart cards as well. (along with the other features...)

Neat idea, though.

Ah yes - BYOD

ITMA

Otherwise known as Bring Your Own Disaster...

ITS Retired

A pin code for a ByOD? Isn't a pin code another name for a password?

ITMA

Erm..... Yup

tfewster

Isn't a pin code another name for a really weak password?

FIFY. Even worse, PIN codes are easy to read by watching someone type them (even if they're not echoed to the screen as in a phone call) and rarely changed

MatthewSt

The main difference is that the PIN code is only valid for that device (unless users have re-used pin codes across devices, but you'd still need one of their devices).

Microsoft on smartphones

Paul Hovnanian

So this affects like what? Four people?

I have no right, by anything I do or say, to demean a human being in his
own eyes. What matters is not what I think of him; it is what he thinks
of himself. To undermine a man's self-respect is a sin.
-- Antoine de Saint-Exupery