News: 1683661512

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft disarms push notification bombers with number matching in Authenticator

(2023/05/09)


Microsoft is hoping to curb a growing threat to multi-factor authentication (MFA) by enforcing a number-matching step for those using Microsoft Authenticator push notifications when signing into services.

Starting this week, Redmond is [1]putting some muscle behind a number-matching feature that it began talking about last year. It said there were rising numbers of cyberattacks using [2]MFA fatigue , also known as MFA push spamming and push bombing.

Two-factor authentication (2FA) and MFA are strategies for verifying users trying to log on to websites, accounts or services, and are part of the larger drive for [3]zero-trust architectures , which take the position that anything or anyone trying to climb onto a network can't be trusted or given access until verified.

[4]

MFA can come in the form of a one-time code you enter, or an app on a linked device that pops up a notification asking if a login attempt is legit. If someone is trying to login as you, you can decline access. If it's you trying to get in, you can approve the login.

[5]

[6]

Attackers are finding ways around MFA protections, such as through phishing, and, in this case, MFA fatigue, a social engineering effort in which attackers use stolen credentials to try to sign into a protected account quickly and repeatedly, overwhelming potential victims with push notifications asking for login approval.

Initially the targeted individual will likely hit the prompt to indicate it isn't them trying to sign in, but may be worn down in the spamming onslaught and eventually accept the login to stop the harassment. Essentially, MFA is supposed to thwart those using stolen login credentials, but in reality, the protection measure can be bypassed by exploiting the human element: spamming users with notifications on their devices until they assume it's a bug and hit accept. At that point, the miscreant is in your account.

[7]

It's a threat Microsoft, among other vendors and security pros, has been tracking for a couple of years. Redmond [8]saw almost 41,000 Azure Active Directory Protection sessions with multiple failed MFA attempts in August 2022, compared with 32,442 a year earlier, and noted that such attacks had "become more prevalent."

MFA fatigue also is one of any number of reasons Microsoft is leaning on in an industry push – and that of others, including [9]Google and Apple – to do away with passwords entirely as a verification tool.

There were some high-profile attacks last year that featured MFA fatigue schemes. The Yanluowang ransomware gang used it in an [10]strike against Cisco while the Lapsus$ group leaked 37GB of source code stolen from Microsoft after compromising an employee via MFA fatigue. [11]Uber was also hit by Lapsus$ via such an attack, it's reported.

[12]Microsoft may charge different prices for Office with or without Teams

[13]Microsoft touts bigger, faster Azure VMs as data deluge grows

[14]AWS, Microsoft make finding important admin info less frustrating

[15]Microsoft helps devs create chatbots – because who needs human interaction anyway?

In October 2022, Microsoft [16]introduced number matching as an option, as well as other security features like location and application context, in Microsoft Authenticator. Now, number matching is automatically being enabled for all push notifications in Authenticator.

"As relevant services deploy, users worldwide who are enabled for Authenticator push notifications will begin to see number matching in their approval requests," the vendor wrote in an Azure support note this week. "Users can be enabled for Authenticator push notifications either in the Authentication methods policy or the legacy multifactor authentication policy" as long as notifications through the mobile app is enabled."

[17]

The note also said that number matching doesn't support push notifications for Apple Watch or Android wearable devices. "Wearable device users need to use their phone to approve notifications when number matching is enabled," Microsoft wrote.

When it's enforced, Authenticator users responding to a MFA push notification will be presented with another number that they'll need to type into whatever app is being logged into to complete the process. Authenticator users will not be able to opt out of the feature. It effectively adds a one-time code element to the push notification approach.

Some services will begin deploying the changes starting this week and "users will start to see number match in approval requests. As services deploy, some may see number match while others don't. To ensure consistent behavior for all users, we highly recommend you enable number match for Authenticator push notifications in advance."

The number matching also will work in other scenarios with Authenticator, including self-service password reset (SSPR), AD FS adapters (on support Windows Server versions), and combined MFA and SSPR registration when setting up Authenticator.

For Windows users who don't use Authenticator, their default sign-in method won't change, according to Redmond. ®

Get our [18]Tech Resources



[1] https://learn.microsoft.com/en-us/azure/active-directory/authentication/how-to-mfa-number-match

[2] https://www.theregister.com/2022/11/03/mfa_fatigue_enterprise_threat/

[3] https://www.theregister.com/2022/07/13/mergers-zero-trust-zscaler/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZFrChJlU-vWG-BXUSVrsnwAAAMU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFrChJlU-vWG-BXUSVrsnwAAAMU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFrChJlU-vWG-BXUSVrsnwAAAMU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFrChJlU-vWG-BXUSVrsnwAAAMU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/defend-your-users-from-mfa-fatigue-attacks/ba-p/2365677

[9] https://www.theregister.com/2023/05/04/google_passkey/

[10] https://www.theregister.com/2022/09/13/cisco_ransomware_data_leaked/

[11] https://www.theregister.com/2022/09/19/uber_admits_breach/

[12] https://www.theregister.com/2023/05/05/microsoft_eu_antitrust_teams_office/

[13] https://www.theregister.com/2023/05/04/microsoft_azure_nvme_instances/

[14] https://www.theregister.com/2023/05/04/aws_microsoft_sysadmin_email_improvements/

[15] https://www.theregister.com/2023/05/02/microsoft_copilot_chat/

[16] https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/advanced-microsoft-authenticator-security-features-are-now/ba-p/2365673

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFrChJlU-vWG-BXUSVrsnwAAAMU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://whitepapers.theregister.com/



Security vs Convenience

FlamingDeath

Is it really that difficult to enter in a 6 digit number?

I’ve never liked the push notification form of 2FA for the sole reason it’s just a matter of time before someone accepts the authentication unwittingly while in a nice safe environment with their legs up and hair down, possibly even a wee bit drunk.

Needing to enter in a code negates any possibility of any miscreants with your password spamming you with “push notifications”

Also, more worryingly still, if an end user is being spammed with 2FA push notifications that should be alarm bells to them and they should probably take it as a given that their password has been compromised.

Assuming they piece this information together.

If your employees do not make this connection, that’s idiotic

ExampleOne

If the problem is bad actors spamming users with authentication requests till they approve the access, why not implement rate limiting on the accounts?

FORTUNE'S GUIDE TO DEALING WITH REAL-LIFE SCIENCE FICTION: #6
What to do...
if a starship, equipped with an FTL hyperdrive lands in your backyard?
First of all, do not run after your camera. You will not have any
film, and, given the state of computer animation, no one will believe
you anyway. Be polite. Remember, if they have an FTL hyperdrive,
they can probably vaporize you, should they find you to be rude.
Direct them to the White House lawn, which is where they probably
wanted to land, anyway. A good road map should help.

if you wake up in the middle of the night, and discover that your
closet contains an alternate dimension?
Don't walk in. You almost certainly will not be able to get back,
and alternate dimensions are almost never any fun. Remain calm
and go back to bed. Close the door first, so that the cat does not
wander off. Check your closet in the morning. If it still contains
an alternate dimension, nail it shut.