Week 5 - Authentication Methods

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/17

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:14 PM on 9/26/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

18 Terms

1
New cards

Password strengths:

  • Ubiquitous and easy to deploy

  • No specialized hardware needed


2
New cards

Password weaknesses:

  • Vulnerable to guessing, credential stuffing, reuse attacks, and phishing

  • Often implemented with poor user policies (e.g., forced complexity, expiration)

  • Users struggle to create/remember strong secrets


3
New cards

Password guidance:

  • Allow long, user-chosen passphrases

  • Eliminate frequent, forced periodic resets unless evidence of compromise exists

  • Screen against breached/common password lists


4
New cards

Hardware One Time Password Authenticators Strengths:

  • Not dependent on user-created secrets

  • No internet connectivity needed


5
New cards

Hardware One Time Password Authenticators Weaknesses:

  • Vulnerable to phishing (codes can be relayed)

  • Codes can be intercepted via malware

  • Device loss requires recovery processes


6
New cards

Hardware One Time Password Authenticators Guidance:

  • Consider pairing OTP authenticators with a user-created PIN

  • Train users to never provide an OTP code to others

  • Ensure codes are short-lived and protected from replay

  • Meets AAL2 when paired with a separate factor


7
New cards

Software One Time Password Authenticators Strengths:

  • Better usability than hardware tokens

  • Still independent of password

  • Widely supported

  • Recoverable via backup codes


8
New cards

Software One Time Password Authenticators Weaknesses:

  • Stored on devices that may be compromised

  • Still phishable; attackers can ask user to read the code

  • Backup/recovery increases attack surface


9
New cards

Software One Time Password Authenticators Guidance:

  • Consider pairing OTP authenticators with a user-created PIN

  • Train users to never provide an OTP code to others

  • Meets AAL2 when paired with a separate factor

  • Secrets should be generated and shared over a secure channel

  • Protect backup codes with the same rigor as the authenticator itself


10
New cards

Out-of-band Authenticators Strengths:

  • Very easy for users

  • No specialized hardware needed

  • Good for low-risk systems


11
New cards

Out-of-band Authenticators Weaknesses:

  • Discouraged at AAL2 and above

  • Susceptible to SIM swapping

  • Interceptable

  • Phishable

  • Relies on external networks


12
New cards

Out-of-band Authenticators Guidance

  • SMS cannot be used above AAL1

  • Push notifications must be cryptographically bound to the verifier

  • OOB channels must be distinct (separate device or comms path)

  • Avoid for sensitive systems


13
New cards

Cryptographic Authenticators (e.g., FIDO2/WebAuthn) Strengths:

  • Phishing-resistant

  • Private keys never leave the authenticator

  • High usability

  • Origin binding prevents login to impostor sites


14
New cards

Cryptographic Authenticators (e.g., FIDO2/WebAuthn) Weaknesses:

  • Requires supported hardware/software ecosystem

  • Backup strategies must be planned


15
New cards

Cryptographic Authenticators (e.g., FIDO2/WebAuthn) Guidance:

  • Preferred method at AAL2 and mandatory at AAL3

  • Key pairs must be generated in hardware and non-exportable

  • Authentication must include proof-of-possession (challenge-response)

  • Allowed as single-factor authentication at AAL2 and required at AAL3

  • Device must offer secure attestation and cloning resistance


16
New cards

Biometrics Strengths:

  • Convenient and fast

  • Unique to each user


17
New cards

Biometrics Weaknesses:

  • Not secret; can be copied or spoofed

  • Cannot be revoked if compromised (obviously)

  • For high-risk systems, may endanger user safety


18
New cards

Biometrics Guidance:

  • Cannot be the sole factor at AAL2 or AAL3

  • Must include presentation attack detection (PAD) to avoid spoofing

  • Must operate with a fallback authenticator if biometric fails

  • Storage and matching must protect biometric templates from theft

  • Match must occur in a secure local environment (device enclave) for AAL2 and above