© All rights reserved.
Nok Nok Nok Nok
  • Solutions
    • Passwordless Authentication
    • Fraud Detection and Prevention -Testing
    • Passkeys
    • Secure Payments
    • Compliance
    • Professional Services
  • Industries
    • Government
    • E-Commerce
    • Financial Services
    • Mobile Network Operators
  • Products
    • Authentication Cloud
    • S3 Suite
    • Smart Analytics Module
    • Smart Sense Module
    • IoT SDK
  • Resources
    • Demo
    • Demonstration – Testing
    • Videos
    • White Papers
    • Testimonials
  • Company
    • About
    • Team
    • Partners
    • Clients
    • Events
    • News
    • Blog
    • Contact Us
    • Support Services
Free Trial
Sign In
Nok Nok
Home / Cybersecurity / On Cyber-Attacks and Authentication Credentials: Cyberdefense’s Weak Underbelly

On Cyber-Attacks and Authentication Credentials: Cyberdefense’s Weak Underbelly

  • Author
    Nok Nok News
  • Published
    29 Jun 2017
  • 0 comments
    Join Conversation
Cybersecurity

The cascade of cyberattacks from the WannaCry ransomware that encrypted hospital computers to the Dyn attack that took down large swaths of the internet, to the most recent GoldenEye (or Petya) malware that is still sweeping the globe, the parade is never-ending. In a recent article in the New York Times, IDT Corporation’s Global CIO Mr. Ben-Oni outlined an attack on his company that is worth reading closely for several key take aways.

A deep investment of millions of dollars in anti-virus, intrusion detection and firewall systems, did not prevent the critical attack that masqueraded as ransomware but was really aimed at stealing employee credentials to create an ongoing compromise of IDT’s systems. According to the article, Mr. Ben-Oni followed advice that he had received from an N.S.A. employ and deployed three firewalls, three antivirus solutions, and three detection systems. Mr. Ben-Oni was rigorous in subscribing to 128 publicly available threat intelligence feeds, 10 subscription threat intelligence feeds (costing IDT hundreds of thousands of dollars annually) and each and every preventative measure he put in place failed to catch the attack.

What is vitally important is that the attackers were after employee credentials. Once you compromise authentication, you have the keys to the kingdom and you can take your time emptying out the vault.

Also, note that the layered network defenses from some of the foremost vendors in the world failed to protect against this attack. Millions of dollars were spend on modern-day detection systems were ineffective in protecting the company.

What can we learn from this? First – we must use Multi-Factor Authentication rather than single credentials – particularly ones that can be harvested and replayed against us. Second, the Cyber-Defense playbook needs to be changed to prioritize the strengthening of credentials over the layering of network defenses. There will always be zero-day vulnerabilities and tools such as the leaked NSA “Double Pulsar” that will be used to get past these network cyber defenses. The integrity of our systems, networks and computing infrastructure at a corporate and national level, relies then on securing the core authentication credentials that are the keys to the kingdom.

The attack demonstrates that network oriented approaches are mere “band-aids” without using some accompanying “antibiotics” – the important first step is to secure authentication and then layer on the network defenses. There’s a failure in critical thinking when we continue to pour hundreds of millions of dollars into a failed defensive strategy while neglecting core defenses. Authentication is under attack as the weak underbelly of cybersecurity.

It has been a while since I looked at the combined dollars going into the network oriented cyber defensive companies relative to those offering strong authentication but I see some tipping points ahead as we start to rethink cyber-defense from the ground up and start to secure authentication. When we founded the FIDO Alliance and worked on its core protocols (FIDO-UAF and subsequently U2F and FIDO2.0) a principal design goal was to prevent scalable attacks by dramatically raising the cost of attacking authentication and we have achieved that quite well.

Beyond this specific attack on IDT, the last Verizon Data Breach report estimated that 81% of cyberattacks involved a stolen or compromised authentication credential – that is a stunning indication of where our underbelly lies. At a recent industry conference, both Google and Microsoft spoke about their identity-aware proxies as a layered defense mechanism for their cloud services. Separately, FIDO Alliance was spoken about extensively by NCCOE, NIST and many private companies such as Microsoft and Google, as a key building block for security & identity. At Nok Nok Labs, we are working on a closer integration of device/user and network authentication. Perhaps the IDT attack and the alarm bells sounded by Mr. Ben-Oni will persuade smart CIOs and boards to actively accelerate changes in their authentication strategy.

Nok Nok News

Related Posts

Navigating Cybersecurity in Operational Technology: Insights from the Joint Cyber Defense Collaborative
Cybersecurity S3 Authentication Suite

Navigating Cybersecurity in Operational Technology: Insights from the Joint Cyber Defense Collaborative

2024 Security Industry Predictions: Consolidation, ROI, and the AI Hype Train
Cybersecurity Opinion

2024 Security Industry Predictions: Consolidation, ROI, and the AI Hype Train

Top 6 Considerations to Build vs. Buy FIDO-based Passkeys
Cybersecurity

Top 6 Considerations to Build vs. Buy FIDO-based Passkeys

Fun and Not so Fun Evolution of Authentication: Nok Nok’s Cybersecurity Month Special Series
Cybersecurity

Fun and Not so Fun Evolution of Authentication: Nok Nok’s Cybersecurity Month Special Series

Leave a Reply (Cancel reply)

Your email address will not be published. Required fields are marked *

*
*

Contact Us

Nok Nok, Inc.
2890 Zanker Rd #203
San Jose, CA 95134

(650) 433-1300

[email protected]

Get Google Maps Directions

Contact and Subscribe

* indicates required

Latest Posts

  • Navigating Cybersecurity in Operational Technology: Insights from the Joint Cyber Defense Collaborative
  • Quantum is Knocking!
  • Nok Nok Announces Innovative Solutions that Simplify Deploying and Managing Passkeys
  • Navigating the Path to Passkeys: One Approach Does Not Fit All

Navigation

  • Subscribe
  • Careers
  • Resources
  • Support

Nok Nok Labs, Nok Nok, and NNL are all trademarks of Nok Nok Labs, Inc. © 2025 Nok Nok Labs, Inc.
FIDO is a trademark of the Fast IDentity Online, (FIDO), Alliance. All rights reserved.
Terms Of Use and Privacy Policy

Demo
Free Trial
Videos
Contact Us
Support

Contact Us: (650) 433-1300 • [email protected]

Copy
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}

Please complete this form to view and download this resource.

Submit to Download Forms

* indicates required
  • 日本語