{"id":9624,"date":"2022-06-15T11:43:39","date_gmt":"2022-06-14T23:43:39","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=9624"},"modified":"2022-06-15T11:43:39","modified_gmt":"2022-06-14T23:43:39","slug":"mfa-is-important-but-it-is-no-silver-bullet","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=9624","title":{"rendered":"MFA is important, but it is no silver-bullet."},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.27.4&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<p>There are no silver bullets. No one can guarantee you won\u2019t be hacked, but we can make it harder.<\/p>\n<h2>We can reduce your cyber-risk by taking reasonable steps to make it harder to hack you.<\/h2>\n<p>The key is to have layers of security, and to keep reviewing the technology in use to ensure it keeps up with a rapidly changing world.<\/p>\n<p>We keep saying that the cyber-protection that seemed excessive a year ago feels inadequate now.<br \/>One of the most important protections is multi-factor authentication, \u201cMFA\u201d or \u201c2FA\u201d. We know it\u2019s annoying and intrusive, but highly effective. Nevertheless, it can be defeated.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_2,1_2&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>Here\u2019s one trick to watch out for. Look out for a call from someone claiming to be from your bank or IT department or similar. They might say something like \u201cbefore I will talk with you, I need you to prove who you are, by giving me your MFA code.\u201d Of course, the second you tell them, they immediately use it and can do whatever they want, from stealing your money, resetting some of your passwords or setting up an impersonation of you.<\/p>\n<p>Here is the sneaky part. The hacker may not even speak the victims language and they don&#8217;t want to call them directly, exposing their own phone number. So the hacker purchases a online system for $400 a month. That system uses Interactive Voice Response to call the victim.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&quot;1_2&quot; _builder_version=&quot;4.17.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_image src=&quot;https:\/\/new.kinetics.co.nz\/wp-content\/uploads\/2022\/06\/CyberRobot.png&quot; title_text=&quot;CyberRobot&quot; _builder_version=&quot;4.17.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&quot;4.17.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_column type=&quot;4_4&quot; _builder_version=&quot;4.17.4&quot; _module_preset=&quot;default&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot;][et_pb_text _builder_version=&quot;4.27.4&quot; _module_preset=&quot;default&quot; hover_enabled=&quot;0&quot; global_colors_info=&quot;{}&quot; theme_builder_area=&quot;post_content&quot; sticky_enabled=&quot;0&quot;]<\/p>\n<h2>Yes, you read that right, robots are stealing MFA codes.<\/h2>\n<p><span style=\"font-size: 14px;\">This technique only works if the hacker already somehow has your username and password, AND you tell them your MFA code.<\/span><\/p>\n<p>Likewise, always check the website you are logged into \u2013 where possible, don\u2019t click on the link in emails but rather type in the URL yourself or use your \u2018favourites\u201d list . We have heard of a situation where hackers copied the login page of a well known NZ bank, and tricked users to go to their fake site, and enter their username, password and MFA code.<\/p>\n<h2>Luckily <a href=\"https:\/\/new.kinetics.co.nz\/cybersecurity\/\">KARE for Security<\/a> can help reduce the risk by checking URLs for you.<\/h2>\n<p>It helps to layer security.\u00a0 In this case, using <a href=\"https:\/\/new.kinetics.co.nz\/cybersecurity\/\">KARE for Security&#8217;s<\/a> web protection checks the URL&#8217;s you access against known databases and reduces the risk of accidently accessing a bad website.<\/p>\n<p>For more information, refer to : <a href=\"https:\/\/www.techrepublic.com\/article\/cybercriminals-automated-bot-bypass-2fa\">https:\/\/www.techrepublic.com\/article\/cybercriminals-automated-bot-bypass-2fa<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There are no silver bullets. No one can guarantee you won\u2019t be hacked, but we can make it harder. We can reduce your cyber-risk by taking reasonable steps to make it harder to hack you. The key is to have layers of security, and to keep reviewing the technology in use to ensure it keeps [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":9629,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-9624","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/9624","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9624"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/9624\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9624"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9624"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9624"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}