Dazzee IT's Shane Naugher and Dom Maxwell explain how multi-factor authentication blocks attackers even when your password has already been leaked or stolen.
Key Takeaways
- Enable multi-factor authentication (MFA) on every account you own, because stolen credentials alone give attackers full access if MFA is not in place.
- If using a personal phone for an authenticator app is a concern at your organization, hardware tokens such as YubiKeys are an affordable alternative that typically cost between $20 and $70.
- Email and business account compromises are far more common than ransomware, and the vast majority of those breaches involve accounts with no MFA enabled.
- Use a unique, complex password of at least 16 characters for every account, and consider a password manager to make that practical.
- Skipping MFA can result in denied cybersecurity insurance claims, making the small upfront cost of hardware tokens a worthwhile investment for any organization.
Full Transcript
Welcome to Give IT To Me Straight
Shane Naugher: Hey guys, and welcome back to another edition of Give IT To Me Straight, where we walk through a lot of the common questions and IT issues we hear from our clients as well as prospects. I'm really excited to be joined again by Dom Maxwell from our team. Dom, thanks for taking the time to hop on with me today. I'm excited to dive through the topics we're gonna cover today.
Dom Maxwell: Of course. Always happy to be a part of the podcast.
What Is Multi-Factor Authentication and Why Do We Need It?
Shane Naugher: Well, Dom, one of the things I wanted to cover today, it's funny because we were talking internally. I actually recorded a video on this almost 10 years ago, and it's still a relevant topic today. It's still something we have trouble getting end users to understand and adopt, but it is so critically important, and that is the topic of multi-factor authentication, or MFA. So Dom, can you walk through what MFA is and why we need it?
Dom Maxwell: So multi-factor authentication is just another layer of protection on business critical accounts, emails, and other places where you may need to sign in. It goes beyond just a password that you use to sign in. It's also an additional layer outside of that, so that if for some reason your account is compromised due to a dark web breach or anything similar, and your password is out there, your MFA would then be another layer on top of that to protect you. And it comes in many different forms.
What Happens When Your Password Gets Leaked?
Shane Naugher: And I think it's important because the practice we preach all the time is never reuse passwords across multiple sites, and set up a complex password that's at least 16 characters. But inevitably, we know that at least 70% of users reuse passwords across multiple sites. So I get it. If you're not using a password manager, it's hard to come up with unique passwords. And a lot of times those passwords get exposed, posted to the dark web, and now bad actors can get in there and actually get your username and password. To your point, if they have the username and password and multi-factor authentication is not turned on, is there any other way to prevent them from getting access to your account?
Dom Maxwell: Typically, no. Once your credentials have been compromised, that's it. And in a lot of cases, you may not even know that it's been compromised.
Shane Naugher: And that's where we find most people sit today. They're not totally aware of what's out there on the dark web, or if their user credentials have been compromised. So a lot of times this happens without people's knowledge. So walk us through how multi-factor authentication protects against that. What does it actually do?
Dom Maxwell: Yeah, so I'm sure a lot of users and a lot of people watching the podcast are probably familiar, but one of the most common ways it's implemented is through phone usage. You'll have an application that is tied to your login through your email. You'll enter your password, and you'll be prompted to then interact with this specific app on your phone that you've set up and that's linked to your account. It'll either display a number and there'll be six numbers that you'll have to enter into wherever you're signing in, or it's a push notification that you then have to approve. But it's just a second layer of, are you sure this is you signing into your account?
Shane Naugher: And that's important because even with a username and password, if those are compromised, if you've got multi-factor authentication set up, it's gonna deny access. And the key thing around this is that those codes are time-bound, meaning most of the time those one-time numeric codes rotate about every 30 seconds, depending on the app.
Dom Maxwell: Yeah.
Shane Naugher: So if you don't catch it in that window, it's gonna automatically expire and you won't get access effectively. With Microsoft, they have their own authenticator app, and to your point, it may push a notification to your registered device that you actually have to click accept on. And Microsoft isn't the only one. Google also offers the same thing. They have an authentication app that'll do push notifications. I think just about everybody here at the office uses Duo, and it's been great having it all in one location.
Why Do People Push Back on Multi-Factor Authentication?
Dom Maxwell: I think a lot of folks view it as kind of slightly inconvenient.
Shane Naugher: Well, that kind of leads me to my next question. Like I say, we talked about this 10 years ago. Why is there so much pushback when it comes to implementing something that seems fairly simple?
Dom Maxwell: So let me use my mother as a great example here. Before I started working here at Dazzee IT, I was the IT person for our family. My mom was prompted by her Apple device to set up another layer of authentication on top of her sign-in, and she's like, "Do I really have to do this?" I think in her eyes, she knows her password, she knows her username, and she can get into her account fairly quickly if she needs to. But then if you have to take another 10 seconds to grab this number, and then you miss that number, and now you have to wait for it to cycle back around a second time.
Dom: And I think they just view it as an inconvenience, whether it be time-based or some frustrations that may come along with it.
Shane Naugher: Yeah, you bring up a really good point. A couple of years ago I had the pleasure of meeting Marcus Lemonis from the TV show The Profit. We were having a session where we could ask questions of him, and he actually had an instance where his network was compromised. One of the key takeaways I had from that discussion was he said he never really understood or respected just how violated he felt as an individual knowing that someone else got into his systems and into his accounts. And I think until you get something like that that happens and you realize, "Hey, someone could be getting access to my data," and most people their argument is, "Hey, I don't have anything all that sensitive." But when you really look at it, the communications between your family, your financial information, pictures, anything that could be leveraged, when you look at the totality of what could be exposed, a lot of times people minimize that until it happens. And when it does, it's almost a sheer panic that sets in, like oh my gosh, what did they get access to? And so it is one more step, it does slow things down, minimally, but it...
Dom: Yeah, it's really negligible. Yeah.
Shane Naugher: And so I know a lot of people look at that as, like you say, "I don't want to have another step," but it really is so critical in enabling the protections on your account. I know that we work a lot with cities and nonprofits, and a lot of times they don't issue company-owned cell phones. And I know sometimes we'll get pushback around that. Can you dive into what that typically looks like and what the questions are?
Why Do Employees Push Back on Using Personal Phones for MFA?
Dom: So, like we said, most of them utilize an application that's downloaded on a lot of different mobile devices now. I know personally I have work and personal things related on my cell phone. I think that's just part of working in technology, and it's understood that there's gonna be some overlap. But when you get someone who works for a city and they feel like, when they're at the office that's their time at the office, and then their phone is their phone, they feel like entering some kind of work credential on their cell phone or having an application that's tied to work is somewhat invasive. That seems to be the main pushback. They feel like they shouldn't have to put something on their phone that's work-related. If it was needed for work, it'd be provided by the place that they work.
Shane Naugher: Yeah. Especially with cities or municipalities, this show's not about legal advice and we certainly don't want to dive into that aspect, but I know we have heard cities discuss the fact that if people put work information on, or use their personal phone for work purposes, if there ever becomes any type of legal investigation, that could be subject to that legal case and it could expose that entire phone. I understand in some of those scenarios where there is some hesitancy, and I can understand that risk. If you're in an organization where you have those concerns and you don't want your end users having to use their own mobile phones to do this, and you don't have the budget to issue company phones for that, are there any options beyond a mobile phone app?
What Are the Alternatives to Mobile Authenticator Apps?
Dom: Yep. There are quite a few different methods. I think the most popular is a hardware token. It functions as a device specifically that you have to interact with physically. A lot of times it's what's called a YubiKey. You plug this device into a USB slot on the computer you're signing in with. Once you attempt to sign in, it's linked to your account and it will ensure that you have to touch that key. There's physical interaction with this device that says, "Yeah, I'm attempting to sign in." Along with that, Microsoft specifically uses Windows Hello, which can be facial recognition. If your device has other biometric scans like a fingerprint reader, those are also available and can be tied to those same types of accounts.
Shane Naugher: Perfect. And that's when we get to those instances where we understand you don't want your end users having to use their personal devices, a legitimate argument in that case. One of the key things that we push is that there are other options. Those hardware devices, like the YubiKeys you referenced, they're not horribly expensive depending on the model that you get. You know, $20 or $30 on up to probably $70 depending on compliance requirements. But in terms of risk versus reward, especially when almost all insurers now are asking whether you require multi-factor authentication for all applications, if you answer that incorrectly because you have a certain subset of users that don't want to use their personal phones, that could cause your claim to be denied if there's ever an issue that occurs. So when you look at the investment of those hardware tokens versus the risk, it could drive up your insurance premiums, and worst case scenario you have an insurance claim submitted that's denied. It's a relatively inexpensive trade-off to make sure that you have the appropriate protections in place.
Dom: The level of security they provide is invaluable in the long run versus the upfront monetary cost that may be involved.
Shane Naugher: Yeah.
Is Ransomware Really the Biggest Threat?
Shane Naugher: A lot of people when I talk to them say, "We're familiar and worried about ransomware." But working on the front lines of helping our clients and talking with people that are having issues, most of what we hear when it comes to cybersecurity isn't about ransomware, is it?
Dom: I think ransomware is the big bad, the biggest scary thing that people in the public aren't aware of can happen. But it's far from what we see most commonly. Most commonly it's an email compromise, a email or a business account compromise that maybe some users are unaware of, but we have tools involved that will alert us, and then they can alert them and lock down accounts. But more often than not, it's the small personal account, whether it be your personal email, your work email. Those things are where compromises are most likely to happen.
Why Is Multi-Factor Authentication So Important?
Shane Naugher: And most of that, when we dig into it, I would say over 90% of those instances are accounts that don't have multi-factor turned on. It just makes you pretty much a sitting duck. It's not a matter of will this happen to you, it is when and how many times until you enable it.
Dom: Yep. And as far as businesses go, you may have some users, and I think there are a few folks that'll be like, "Well, I can't do it this way," or, "My account's already secure. I'm conscious enough not to click on that link or otherwise." But like you said, it's not an if it's gonna happen, it's when.
Shane Naugher: This is such a huge topic. We've talked about this for years and we'll probably be talking about it for years into the future, until technology makes this transparent, whether it goes off of biometrics for everything. Hopefully we get to a point where it's not as obtrusive or an additional step. But until then, I can't emphasize enough the importance of doing this on every account that you have. If you guys have questions on how to do these setups with hardware tokens or what the options are, let us know. Dom or Logan or one of the guys would be more than happy to jump in and talk with you about how to enable that, what the cost looks like, and just answer any questions around it. Dom, it's always great to talk to you. I appreciate your insight and the advice that you bring to the podcast. I look forward to connecting with you on the next one.
Dom: Thank you very much for having me again. I feel like I must have done something right to be able to get back on a second episode, so I'll keep it up.
Shane Naugher: Absolutely. All right, Dom, we'll see you on the next one.
Dom: All right.
Ready to Stop Worrying About IT?
Join hundreds of Missouri organizations who trust Dazzee IT as their technology partner. 25+ years, 80% same-day resolution.
