1/17
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Password strengths:
Ubiquitous and easy to deploy
No specialized hardware needed
Password weaknesses:
Vulnerable to guessing, credential stuffing, reuse attacks, and phishing
Often implemented with poor user policies (e.g., forced complexity, expiration)
Users struggle to create/remember strong secrets
Password guidance:
Allow long, user-chosen passphrases
Eliminate frequent, forced periodic resets unless evidence of compromise exists
Screen against breached/common password lists
Hardware One Time Password Authenticators Strengths:
Not dependent on user-created secrets
No internet connectivity needed
Hardware One Time Password Authenticators Weaknesses:
Vulnerable to phishing (codes can be relayed)
Codes can be intercepted via malware
Device loss requires recovery processes
Hardware One Time Password Authenticators Guidance:
Consider pairing OTP authenticators with a user-created PIN
Train users to never provide an OTP code to others
Ensure codes are short-lived and protected from replay
Meets AAL2 when paired with a separate factor
Software One Time Password Authenticators Strengths:
Better usability than hardware tokens
Still independent of password
Widely supported
Recoverable via backup codes
Software One Time Password Authenticators Weaknesses:
Stored on devices that may be compromised
Still phishable; attackers can ask user to read the code
Backup/recovery increases attack surface
Software One Time Password Authenticators Guidance:
Consider pairing OTP authenticators with a user-created PIN
Train users to never provide an OTP code to others
Meets AAL2 when paired with a separate factor
Secrets should be generated and shared over a secure channel
Protect backup codes with the same rigor as the authenticator itself
Out-of-band Authenticators Strengths:
Very easy for users
No specialized hardware needed
Good for low-risk systems
Out-of-band Authenticators Weaknesses:
Discouraged at AAL2 and above
Susceptible to SIM swapping
Interceptable
Phishable
Relies on external networks
Out-of-band Authenticators Guidance
SMS cannot be used above AAL1
Push notifications must be cryptographically bound to the verifier
OOB channels must be distinct (separate device or comms path)
Avoid for sensitive systems
Cryptographic Authenticators (e.g., FIDO2/WebAuthn) Strengths:
Phishing-resistant
Private keys never leave the authenticator
High usability
Origin binding prevents login to impostor sites
Cryptographic Authenticators (e.g., FIDO2/WebAuthn) Weaknesses:
Requires supported hardware/software ecosystem
Backup strategies must be planned
Cryptographic Authenticators (e.g., FIDO2/WebAuthn) Guidance:
Preferred method at AAL2 and mandatory at AAL3
Key pairs must be generated in hardware and non-exportable
Authentication must include proof-of-possession (challenge-response)
Allowed as single-factor authentication at AAL2 and required at AAL3
Device must offer secure attestation and cloning resistance
Biometrics Strengths:
Convenient and fast
Unique to each user
Biometrics Weaknesses:
Not secret; can be copied or spoofed
Cannot be revoked if compromised (obviously)
For high-risk systems, may endanger user safety
Biometrics Guidance:
Cannot be the sole factor at AAL2 or AAL3
Must include presentation attack detection (PAD) to avoid spoofing
Must operate with a fallback authenticator if biometric fails
Storage and matching must protect biometric templates from theft
Match must occur in a secure local environment (device enclave) for AAL2 and above