{"id":1925,"date":"2020-03-24T12:11:52","date_gmt":"2020-03-24T08:11:52","guid":{"rendered":"https:\/\/www.techxmedia.com\/?p=1925"},"modified":"2025-04-18T00:22:24","modified_gmt":"2025-04-17T20:22:24","slug":"work-from-home-improve-security-mfa","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/work-from-home-improve-security-mfa\/","title":{"rendered":"Work from home: Improve your security with MFA"},"content":{"rendered":"\n<p><strong><em>By Cameron\nCamp, security researcher at ESET<\/em><\/strong><\/p>\n\n\n\n<p>If you happen to be <a href=\"https:\/\/www.welivesecurity.com\/2020\/03\/16\/covid19-forced-workplace-exodus\/\">working from home due to the<\/a><a href=\"https:\/\/techxmedia.com\/tag\/covid_19\/\"> COVID-19<\/a><a href=\"https:\/\/www.welivesecurity.com\/2020\/03\/16\/covid19-forced-workplace-exodus\/\"> pandemic<\/a>, you should beef up your logins with Multi-Factor Authentication (MFA), or sometimes called <a href=\"https:\/\/www.welivesecurity.com\/2017\/07\/03\/two-factor-authentication-underutilized-security-measure-businesses\/\">Two-Factor Authentication<\/a> (2FA). That way, you don\u2019t have to entrust your security to a password alone. Easy to hack, steal, leak, rinse and repeat, passwords have become pass\u00e9 in the security world; it\u2019s time to dial in your MFA.<\/p>\n\n\n\n<p>That means you have something <em>besides<\/em> just a password. You may have seen MFA in action when you\ntry to log into your bank and you receive an access code on your smartphone that\nyou must also enter to verify it\u2019s really you who is logging in. While it\u2019s an\nextra step, it becomes exponentially more difficult for bad guys to get access\nto your account, even if they have a password that was compromised in a breach\nor otherwise.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What are your options?<\/h2>\n\n\n\n<p>The good news is that MFA is no longer super-tough to use.\nHere, we look at a few different popular ways to use it. If you need to work\nremotely now and log into a central office to collaborate with co-workers, this\nis a nice way to beef up the security of those connections.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Physical token<\/h3>\n\n\n\n<p>This means you have something like a key fob, security USB\nkey or the like, which can be used to generate a very secure passcode that\u2019s\nall-but-impossible to break (unless you have a quantum computer handy). Nowadays,\nthings like YubiKey or Thetis are available for less than US$50 and are very\nwidely supported if you\u2019re logging into your own corporate office technology,\nonline office applications and a host of other cloud applications. It means\nyour normal login will ask for a password, but also the code generated by your\ndevice, which is often physically small enough to get lost in a pants pocket, so\nsome folks hang them on their keychain for safekeeping.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Mobile phone<\/h3>\n\n\n\n<p>Nowadays you probably carry a mobile device around most of\nthe time, which is a good argument for using it to boost your MFA security\nstance. For example, you can download an authentication app such as Authy, Google\nAuthenticator, or ESET Secure Authentication. Whatever you choose, make sure it\nhas a solid history, security-wise, since it needs to reside on your\nsmartphone, which we now know can become compromised as well, thereby\nundermining your other security efforts.<\/p>\n\n\n\n<p>It\u2019s worth noting that spam SMS messages on your smartphone\ncan trick some users into voluntarily compromising their own accounts, so stay\non the lookout if you use this. Of course, reputable mobile security software can\nhelp if you\u2019re concerned with security problems on the platform itself.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\n<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Biometrics<\/h3>\n\n\n\n<p>It\u2019s very hard to fake a fingerprint or retinal scan <em>and<\/em>\nmake sure it offers a solid factor in MFA. Nowadays, lots of devices have\nbuilt-in biometric readers that can get an image of your face from your\nsmartphone taking your picture, or scan your fingerprint, so it\u2019s not hard to\nimplement this on a device you probably already have. Some folks steer away due\nto privacy concerns, which promises to be an ongoing conversation. Also, while\nyou can reset a password, if a provider gets hacked it is notoriously difficult\nto reset your face (old spy movie plots, anyone?).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Closing thoughts<\/h2>\n\n\n\n<p>The important thing with MFA is that you pick one that suits\nyour goals and one that is easy for you to include in your routine. I have a\nvery good lock on my front door, but it\u2019s very hard to use, so often my wife\ncatches me leaving it open, which isn\u2019t very secure, is it? Good security you\ndon\u2019t use can\u2019t protect you.<\/p>\n\n\n\n<p>In the event of a breach, MFA can offer side benefits as\nwell. If you are notified that your password is compromised, there\u2019s a very\ngood chance they don\u2019t also have one of your other factors, so successful hack\nattacks should drop precipitously if MFA is correctly implemented. Use an MFA\nsolution and enjoy technology more safely.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>You may have seen MFA in action when you try to log into your bank and you receive an access code on your smartphone that you must also enter to verify it\u2019s really you who is logging in. While it\u2019s an extra step, it becomes exponentially more difficult for bad guys to get access to your account, even if they have a password that was compromised in a breach or otherwise.<\/p>\n","protected":false},"author":8,"featured_media":9048,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[9618],"tags":[964,965,723,724,963,894,838],"contributor":[],"class_list":["post-1925","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-editors-pick","tag-2fa","tag-authentication","tag-coronavirus","tag-covid_19","tag-mfa","tag-pandemic","tag-remote_working"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/03\/mfa-techxmedia.jpg","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1925","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=1925"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/1925\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/9048"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=1925"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=1925"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=1925"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=1925"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}