According to a PayPal notice of security incident dated January 18, attackers got unauthorized access to the accounts of thousands of users between December 6 and 8, 2022. The total number of accounts that were accessed by threat actors using a credential stuffing attack is reported as being 34,942. While accepting that PayPal is seemingly doing the best it can for the customers involved in this security incident by recommending password changes, Jasson Casey, chief technology officer at Beyond Identity insists that “passwords – whether unique or complex – are fundamentally flawed.” Instead, Casey says, organizations should be moving to phishing-resistant credentials such as the FIDO Alliance standard blueprints.


More

Microsoft News: Passwordless is here and at scale

Microsoft’s blog post explores Accenture’s journey as they adopted passwordless authentication. With cyber-attacks on the…

Read More →

Associations Now: Tech Talk: 30 Technology Terms Everyone Should Know

Passkey – A new type of security technology being introduced by major vendors such as…

Read More →

Security Boulevard: What is a Zero Trust Environment? | HYPR

An effective Zero Trust environment requires an authentication system that can be relied upon to…

Read More →