What you know, what you have and what you are: MFA in the modern age

No ratings

Presented at BSidesChicago 2019 by

A simple username and password are not enough to protect accounts and vital assets anymore. Time and time again, we see various types of accounts being compromised due to password reuse, phishing, smishing and vishing scams and overall poor password hygiene.This session will discuss different types of multi-factor authentication (MFA) such as hardware keys, smart cards, SMS and application-based factors. The session will explain the differences between HOTP, TOTP and PIV credentials and will cover about the pros and cons of each, the vulnerabilities and the various ways that they can be leveraged to help protect accounts.