Cargando…

Hacking multifactor authentication /

"Multi-Factor Authentication (MFA) is spreading like wildfire across digital environments. However, hundreds of millions of dollars have been stolen from MFA-protected online accounts. How? Most people who use multifactor authentication (MFA) have been told that it is far less hackable than oth...

Descripción completa

Detalles Bibliográficos
Clasificación:Libro Electrónico
Autor principal: Grimes, Roger A. (Autor)
Formato: Electrónico eBook
Idioma:Inglés
Publicado: Indianapolis, IN : John Wiley & Sons, Inc., [2021]
Temas:
Acceso en línea:Texto completo (Requiere registro previo con correo institucional)

MARC

LEADER 00000cam a2200000 i 4500
001 OR_on1198019471
003 OCoLC
005 20231017213018.0
006 m o d
007 cr cnu---unuuu
008 200929s2021 inua o 001 0 eng d
040 |a YDX  |b eng  |e rda  |e pn  |c YDX  |d TEFOD  |d EBLCP  |d DG1  |d N$T  |d YDXIT  |d OCLCF  |d OCLCO  |d HRM  |d GPM  |d OCLCO  |d NBJ  |d OCLCO  |d OCLCQ  |d IEEEE  |d OCLCQ  |d UPM  |d OCLCQ  |d ORMDA  |d LANGC  |d OCLCQ 
020 |a 9781119672357  |q (electronic book  |q oBook) 
020 |a 111967235X  |q (electronic book  |q oBook) 
020 |a 9781119672340  |q (electronic book) 
020 |a 1119672341  |q (electronic book) 
020 |a 9781119650805  |q (electronic book) 
020 |a 1119650801  |q (electronic book) 
020 |z 1119650798 
020 |z 9781119650799 
024 7 |a 10.1002/9781119672357  |2 doi 
029 1 |a AU@  |b 000068068981 
035 |a (OCoLC)1198019471 
037 |a F94E0825-B214-4259-8F76-4A4E6FB0546C  |b OverDrive, Inc.  |n http://www.overdrive.com 
037 |a 9820872  |b IEEE 
037 |a 9781119650799  |b O'Reilly Media 
050 4 |a QA76.9.A25  |b G75 2021 
082 0 4 |a 005.8  |2 23 
049 |a UAMI 
100 1 |a Grimes, Roger A.,  |e author. 
245 1 0 |a Hacking multifactor authentication /  |c Roger A. Grimes. 
264 1 |a Indianapolis, IN :  |b John Wiley & Sons, Inc.,  |c [2021] 
300 |a 1 online resource (xxxi, 542 pages) :  |b illustrations 
336 |a text  |b txt  |2 rdacontent 
337 |a computer  |b c  |2 rdamedia 
338 |a online resource  |b cr  |2 rdacarrier 
520 |a "Multi-Factor Authentication (MFA) is spreading like wildfire across digital environments. However, hundreds of millions of dollars have been stolen from MFA-protected online accounts. How? Most people who use multifactor authentication (MFA) have been told that it is far less hackable than other types of authentication, or even that it is unhackable. You might be shocked to learn that all MFA solutions are actually easy to hack. That's right: there is no perfectly safe MFA solution. In fact, most can be hacked at least five different ways. Hacking Multifactor Authentication will show you how MFA works behind the scenes and how poorly linked multi-step authentication steps allows MFA to be hacked and compromised. This book covers over two dozen ways that various MFA solutions can be hacked, including the methods (and defenses) common to all MFA solutions. You'll learn about the various types of MFA solutions, their strengthens and weaknesses, and how to pick the best, most defensible MFA solution for your (or your customers') needs. Finally, this book reveals a simple method for quickly evaluating your existing MFA solutions. If using or developing a secure MFA solution is important to you, you need this book." 
505 0 |a Introduction -- Who This Book Is For -- What Is Covered in This Book? -- MFA Is Good -- How to Contact Wiley or the Author -- Part I Introduction -- Chapter 1 Logon Problems -- It's Bad Out There -- The Problem with Passwords -- Password Basics -- Identity -- The Password -- Password Registration -- Password Complexity -- Password Storage -- Password Authentication -- Password Policies -- Passwords Will Be with Us for a While -- Password Problems and Attacks -- Password Guessing 
505 8 |a Password Hash Cracking -- Password Stealing -- Passwords in Plain View -- Just Ask for It -- Password Hacking Defenses -- MFA Riding to the Rescue? -- Summary -- Chapter 2 Authentication Basics -- Authentication Life Cycle -- Identity -- Authentication -- Authorization -- Accounting/Auditing -- Standards -- Laws of Identity -- Authentication Problems in the Real World -- Summary -- Chapter 3 Types of Authentication -- Personal Recognition -- Knowledge-Based Authentication -- Passwords -- PINS -- Solving Puzzles -- Password Managers -- Single Sign-Ons and Proxies -- Cryptography -- Encryption 
505 8 |a Public Key Infrastructure -- Hashing -- Hardware Tokens -- One-Time Password Devices -- Physical Connection Devices -- Wireless -- Phone-Based -- Voice Authentication -- Phone Apps -- SMS -- Biometrics -- FIDO -- Federated Identities and APIs -- OAuth -- APIs -- Contextual/Adaptive -- Less Popular Methods -- Voiceover Radio -- Paper-Based -- Summary -- Chapter 4 Usability vs. Security -- What Does Usability Mean? -- We Don't Really Want the Best Security -- Security Isn't Usually Binary -- Too Secure -- Seven-Factor MFA -- Moving ATM Keypad Numbers -- Not as Worried as You Think About Hacking 
505 8 |a Unhackable Fallacy -- Unbreakable Oracle -- DJB -- Unhackable Quantum Cryptography -- We Are Reactive Sheep -- Security Theater -- Security by Obscurity -- MFA Will Cause Slowdowns -- MFA Will Cause Downtime -- No MFA Solution Works Everywhere -- Summary -- Part II Hacking MFA -- Chapter 5 Hacking MFA in General -- MFA Dependency Components -- Enrollment -- User -- Devices/Hardware -- Software -- API -- Authentication Factors -- Authentication Secrets Store -- Cryptography -- Technology -- Transmission/Network Channel -- Namespace -- Supporting Infrastructure -- Relying Party 
505 8 |a Federation/Proxies -- Alternate Authentication Methods/Recovery -- Migrations -- Deprovision -- MFA Component Conclusion -- Main Hacking Methods -- Technical Attacks -- Human Element -- Physical -- Two or More Hacking Methods Used -- "You Didn't Hack the MFA!" -- How MFA Vulnerabilities Are Found -- Threat Modeling -- Code Review -- Fuzz Testing -- Penetration Testing -- Vulnerability Scanning -- Human Testing -- Accidents -- Summary -- Chapter 6 Access Control Token Tricks -- Access Token Basics -- Access Control Token General Hacks -- Token Reproduction/Guessing -- Token Theft 
500 |a Includes index. 
588 0 |a Online resource; title from digital title page (viewed on December 07, 2020). 
590 |a O'Reilly  |b O'Reilly Online Learning: Academic/Public Library Edition 
650 0 |a Hacking. 
650 0 |a Hackers. 
650 0 |a Cryptography. 
650 0 |a Computers  |x Access control  |x Testing. 
650 0 |a Computer networks  |x Security measures. 
650 0 |a Computer security. 
650 2 |a Computer Security 
650 6 |a Piratage informatique. 
650 6 |a Pirates informatiques. 
650 6 |a Cryptographie. 
650 6 |a Réseaux d'ordinateurs  |x Sécurité  |x Mesures. 
650 6 |a Sécurité informatique. 
650 7 |a Computer networks  |x Security measures.  |2 fast  |0 (OCoLC)fst00872341 
650 7 |a Computer security.  |2 fast  |0 (OCoLC)fst00872484 
650 7 |a Computers  |x Access control  |x Testing.  |2 fast  |0 (OCoLC)fst00872787 
650 7 |a Cryptography.  |2 fast  |0 (OCoLC)fst00884552 
650 7 |a Hackers.  |2 fast  |0 (OCoLC)fst00872150 
650 7 |a Hacking.  |2 fast  |0 (OCoLC)fst01909643 
776 0 8 |i Print version:  |a Grimes, Roger A.  |t Hacking multifactor authentication.  |d Indianapolis, IN : John Wiley & Sons, Inc., [2021]  |z 9781119650799  |w (OCoLC)1119761240 
856 4 0 |u https://learning.oreilly.com/library/view/~/9781119650799/?ar  |z Texto completo (Requiere registro previo con correo institucional) 
938 |a ProQuest Ebook Central  |b EBLB  |n EBL6357201 
938 |a EBSCOhost  |b EBSC  |n 2634886 
938 |a YBP Library Services  |b YANK  |n 16981285 
994 |a 92  |b IZTAP