Is Using an Authenticator App on the Same Device as the Passwordless Application a True 2FA?

I am building an application that a user can receive an access to by an internal worker. This works using a magic link, where the user will receive a one time link to authenticate in the app. Now I want the application to be secured with 2… Continue reading Is Using an Authenticator App on the Same Device as the Passwordless Application a True 2FA?

Microsoft Authenticator Now Blocks Suspicious MFA Notifications

Microsoft recently introduced a new feature in its Authenticator app, designed to enhance user security and combat MFA fatigue attacks. The new security configuration was rolled out in September, allowing users to suppress pop-up notifications for potentially suspicious login requests. Typically, Microsoft Authenticator users who attempt to log into an account or a service receive…

The post Microsoft Authenticator Now Blocks Suspicious MFA Notifications appeared first on Petri IT Knowledgebase.

Continue reading Microsoft Authenticator Now Blocks Suspicious MFA Notifications

Getting Time-OTP Secret Key from Activation and Serial keys [closed]

I recently registered with a bank that has an online banking platform. The platform website requires login with a proprietary OTP generator app. To activate this application, the bank sent me two numbers, both private:
Serial key: XXXXX-XX… Continue reading Getting Time-OTP Secret Key from Activation and Serial keys [closed]

Microsoft Authenticator Enables Number Matching By Default to Block MFA Fatigue Attacks

Last year, Microsoft released support for number matching in push…

The post Microsoft Authenticator Enables Number Matching By Default to Block MFA Fatigue Attacks appeared first on Petri IT Knowledgebase.

Continue reading Microsoft Authenticator Enables Number Matching By Default to Block MFA Fatigue Attacks

What, if anything, can a person accomplish who has intercepted an emailed QR image for Authenticator?

A web hosting company has emailed me a QR code so I can have Authenticator generate a 6-digit PIN to use as the second factor after I’ve logged into my portal with username and password. What, if anything, could a person accomplish who had… Continue reading What, if anything, can a person accomplish who has intercepted an emailed QR image for Authenticator?