VIA POLITICO Morning Cybersecurity Report 10/6/17

NOW THAT’S WHAT I’M TOKEN ABOUT — The Social Security Administration should let Americans add an extra layer of hack-proof protection to the information they provide the agency, according to a leading cyber-focused lawmaker. In a letter to acting SSA Commissioner Nancy Berryhill, Oregon Sen. Ron Wyden said the agency should let people use physical tokens for two-factor authentication on their accounts. Unlike the most common two-factor approaches — text messages and authenticator apps — these tokens are “resistant to all phishing,” Wyden wrote. He pointed out that the agency had already started moving in this direction by making two-factor authentication mandatory for all accounts in June, and he commended the agency for adding a security feature to its website that would make it harder for cyber criminals to impersonate the government in phishing emails. The logical next step, he wrote, is the token-based Universal 2nd Factor, or U2F, standard. “Given the low cost of implementation and strong additional protection that U2F provides, I urge SSA to consider supporting U2F on an opt-in basis for workers and beneficiaries,” Wyden told Berryhill.

Read the story: https://www.politico.com/tipsheets/morning-cybersecurity/2017/10/06/latest-reported-nsa-cyber-tool-theft-raises-contractor-kaspersky-concerns-222693

Read the letter: https://www.finance.senate.gov/imo/media/doc/100517%20RW%20to%20SSA%20U2F.pdf


More

Wired: How Passkeys Work—and How to Use Them

Passwords suck. They’re hard to remember, but worse is playing the ever-evolving game of cybersecurity…

Read More →

Mastercard: Unlock your key to a more secure checkout

Unlock your key to a more secure checkout. Use your unique payment passkey to secure…

Read More →

Enterprise IT News: Why APAC can lead the world in FIDO and passkey adoption

Asia-Pacific (APAC) is one of the most-attacked regions globally — accounting for 34 per cent…

Read More →


123312 Next

Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.