← กลับบทอ่าน5.IT Security Defense against the digital dark arts
T0675 · ข้อความต้นทางภาษาอังกฤษ
ไฟล์ transcript ต้นทาง · subtitle (26).txt
หน้านี้แสดงข้อความจากไฟล์ต้นทางที่ผู้ใช้ให้ไว้เพื่อเทียบแนวคิด คำอธิบายภาษาไทยในหนังสือเป็นการเรียบเรียงใหม่ ไม่ได้แปลข้อความนี้ทั้งไฟล์
Multi-factor authentication is a system where users are authenticated by presenting multiple pieces of information or objects. The many factors that comprise a multi-factor authentication system can be categorized into three types; something you know, something you have, and something you are. Ideally, a multi-factor system will incorporate at least two of these factors. Something you know would be something like a password or a pin for your bank or ATM card. Something you have would be a physical token like your ATM or bank card. Something you are would be a piece of biometric data, like a fingerprint or iris scan. The premise behind multi-factor authentication is that an attacker would find it much more difficult to steal or clone multiple factors of authentication, assuming different types are used. If multiple passwords are used, security isn't enhanced by that much. This is because passwords, however many, are still susceptible to phishing or keylogging attacks. By using a password in conjunction with a security token is a game changer. Even if the password is compromised by a phishing attack, the attacker would also need to steal or clone the physical token to be able to access the account. That's much less likely to happen. Physical tokens can take a few different forms. Common ones include a USB device with a secret token on it, a standalone device which generates a token, or even a simple key used with a traditional lock. A physical token that's commonly used generates a short-lived token, typically a number that's entered along with a username and password. This number is commonly called a onetime password or OTP, since it's short-lived and constantly changing value. An example of this is the RSA SecureID token. It's a small battery-powered device with an LCD display that shows a onetime password that's rotated periodically. This is a time-based token, sometimes called a TOTP, and operates by having a secret seed or randomly generated value on the token that's registered with the authentication server. This seed value is used in conjunction with the current time to generate a onetime password. Now, as long as the user has possession of their token or can view the display of the token, they're able to log in. I should also call out that the scheme requires the time between the authenticator token and the authentication server to be relatively synchronized. This is usually achieved by using the Network Time Protocol or NTP. An attacker would need to either steal the physical token, or clone the token if they're able to steal the secret seed value. Since a time-based token is synchronized with the server using time, which is not a secret, that would be sufficient for an attacker to clone a token. There are also counter-based tokens which use a secret seed value along with this secret counter value that's incremented every time a onetime password is generated on the device. The value is then incremented on the server upon successful authentication. This is more secure than a time-based tokens for two reasons. First, the attacker will need to recover the seed value and the counter value. Second, the counter value is also incrementing when it's being used. A clone token would only be useful for a short period of time before the counter value changes too much and the clone token becomes unsynchronized from the real token and the server. These token generators can either be physical, dedicated devices, or they can mean app installed on a smartphone that performs the same functionality. Another very common method for handling multi-factor today is that the delivery of onetime password tokens using SMS. But this has been subject to some criticism because of the observed the tax through this channel. The problem with relying on SMS to transmit an additional authentication factor is that you're dependent on the security processes of the mobile carrier. SMS isn't encrypted, nor is it private. It's possible for SMS to be intercepted by a well-funded attacker. Even worse, there have been accounts of SMS-based multi-factor codes being stolen by calling the mobile provider. The attacker impersonates the owner of the line of service to redirect phone calls and SMS to a phone the attacker controls. If the attacker has already compromised the password and can get SMS redirected to them, they now get full access to the account. Of course, there's a convenience trade-off when you use a physical token. You have to carry around another device in order to authenticate. If the device is lost or damaged, the user won't be able to authenticate until the device is replaced. This also requires support overhead since devices will fail, be lost, run out of batteries, and get out of sync with the server. Using an app on a smartphone addresses some of these issues, but still require some additional support and inconvenience. When prompted to login, the user must retrieve a device or phone from their pocket and manually transcribe the numbers into the authentication page. These generated onetime passwords are also susceptible. A user can be tricked into going to a fake authentication page by sending a phishing email, something along the lines of your account has been compromised, please login and change your password immediately. When the victim enters their credentials in the fake page, including the onetime password, the attacker has all the information needed to take over the account.สารบัญบทอ่าน →