By   ISBuzz Team
Writer , Information Security Buzz | Aug 24, 2022 12:05 am PST

Following the news that: 

Michael Tanaka
Michael Tanaka , Chief Commercial Operator
August 24, 2022 8:06 am

Circumventing MFA altogether can be highly effective. In this case the attacker is simply taking advantage of the confusion that normally follows any policy change. It’s perfectly timed – users are confused and they’re unaware of what is expected of them.

User confusion and expectations also enable another attack mentioned – Push Fatigue. You might wonder why a user would respond to a push notification they didn’t initiate, but they do. Sooner or later, given enough attempts some users will simply press “ok” because they have given up understanding what’s being asked of them, they’re tired and don’t care any-more.

It’s a clear reason why we need to minimise the number of steps to authenticate. Every step introduces the chance of user failure, system failure and attack. Keep it simple, keep it one step.

