Design Flaw Has Microsoft Authenticator Overwriting MFA Accounts, Locking Users Out - Slashdot - Cupbord Get in-depth tech gear coverage at WIRED including news and reviews of the latest gadgets

Design Flaw Has Microsoft Authenticator Overwriting MFA Accounts, Locking Users Out - Slashdot

Please wait 0 seconds...
Scroll Down and click on Go to Link for destination
Congrats! Link is Generated
featured image

Posted by msmash from the security-woes dept.

snydeq writes: CSO Online’s Evan Schuman reports on a design flaw in Microsoft Authenticator that causes it to often overwrite authentication accounts when a user adds a new one via QR scan. “But because of the way the resulting lockout happens, the user is not likely to realize the issue resides with Microsoft Authenticator. Instead, the company issuing the authentication is considered the culprit, resulting in wasted corporate helpdesk hours trying to fix an issue not of that company’s making.”

Schuman writes: “The core of the problem? Microsoft Authenticator will overwrite an account with the same username. Given the prominent use of email addresses for usernames, most users’ apps share the same username. Google Authenticator and just about every other authenticator app add the name of the issuer — such as a bank or a car company — to avoid this issue. Microsoft only uses the username.”

The flaw appears to have been in place since Authenticator was released in 2016. Users have complained about this issue in the past to no avail. In its two correspondences with Schuman, Microsoft first laid blame on users, then on issuers. Several IT experts confirmed the flaw, with one saying, “It’s possible that this problem occurs more often than anyone realizes because [users] don’t realize what the cause is. If you haven’t picked an authentication app, why would you pick Microsoft?”

The time spent on any item of the agenda [of a finance committee] will be in inverse proportion to the sum involved. — C.N. Parkinson

Working…

https://zabollah.com/design-flaw-has-microsoft-authenticator-overwriting-mfa-accounts-locking-users-out-slashdot/
A tech blog focused on blogging tips, SEO, social media, mobile gadgets, pc tips, how-to guides and general tips and tricks

Post a Comment

Oops!
It seems there is something wrong with your internet connection. Please connect to the internet and start browsing again.