Popular on Amzeal
- Human Resources Strategy Forum Celebrates 30 Years Empowering Leaders, Shaping the Next Generation of HR Innovators - 115
- Legionnaire Awarded $3.19M AFWERX Contract to Develop Next Generation Air-refueling System
- Omnitronics Proud to Join NXDN Forum
- Diana Partners With OpsVeda To Leverage AI-ML To Get Closer To Its Consumers
- Phishing Protection Industry Growth, Development and Forecast Report, 2030
- Democracy at Work & The Left Forum Presents Seminar with Professor Richard D. Wolff based on "Understanding Capitalism"
- Ron Johnson Announced as the 39th Black Engineer of the Year
- E.G. Phillips Cinematic Single a Fiery Rebuke to Election Season Chaos Agents
- Allegiant Management Group Launches New Website Following Recent Rebranding
- Inframark Announces New Chief Financial Officer
Similar on Amzeal
- Ledger Wallet: The Secure Crypto Storage Solution Every Investor Needs Today
- ALLTRA SmartChain Partners with Kryptobox.io to Enhance Global Digital Asset Accessibility
- ALLTRA SonicSwap Expands DeFi Opportunities with Weekly Listings and Global Partnerships
- Alana Winns Steps Down as Editor-in-Chief and Chief Content Officer of Career Communications Group
- Boost Crypto Rankings Fast: Exclusive Access to Google News Sites in 36 Hours
- Bloktopia Launches New Virtual Real Estate Service: Prime Investment Opportunities in the Metaverse
- Individual Winners and Company Finalists for GCOI 2024 Announced by the Arizona Technology Council and Arizona Commerce Authority
- DTC Computer Supplies Announces Name Change to DES Technologies
- Transcend Engineering Announces Small Business Innovation Research Phase 2 Award from NOAA
- SureFlow to Showcase AI and Eco-Technology Energy Management Solutions at GITEX 2024
Silent Sector Advises IETF of Major Vulnerability Related to QR Codes Used to Enroll Two-Factor Authentication Processes
Amzeal News/10576845
Millions – Perhaps Tens of Millions – of 2FA Credentials at Risk of Exposure. Global Remediation Likely to Cost Billions of Dollars
SCOTTSDALE, Ariz. - Amzeal -- A significant exposure related to the use of QR codes in two-factor authentication (2FA) processes has been identified and reported to the Internet Engineering Task Force (IETF) by researchers and analysts at Silent Sector (https://silentsector.com), a cybersecurity services company that specializes in providing tailored risk management solutions to mid-market and emerging companies across various industries, including healthcare, financial services, technology, manufacturing, and defense.
The exploit, discovered by Brian Contario, Principal Cybersecurity Architect at Silent Sector, lies in the fact that the QR codes used for 2FA enrollment contain sensitive information, including a secret key and user identifiers, which can be captured and misused if not properly secured.
"These codes have been present for over a decade, potentially affecting millions of users worldwide. While this vulnerability is not widely recognized, once it becomes more widely known, it will likely emerge as an area of focus for malicious actors," says Contario.
There are a number of ways that bad actors could gain access to the secret key information in the QR codes. Potential caches of the data include email, messaging, or cloud storage repositories where the QR codes or enrollment information have been transmitted or stored.
"Many IT shops, managed service providers (MSPs), as well as other business and technology professionals often store or email these QR codes, leaving them open to discovery. In public places, including airports, cafes and co-working spaces, images of the QR code can be captured simply by using cameras with zoom lenses when QR codes are displayed on screens for enrollment," he says.
More on Amzeal News
Scope of the Damage
The potential scale of impact is estimated anywhere from tens to hundreds of millions of affected enrollments. Google Authenticator added support for QR codes approximately 12 years ago.
Millions upon millions of QR code enrollments enabled over the past decade have created a large pool of "data residue" where the digital fingerprints of particular 2FA interactions have been saved and archived.
The enrollment processes were originally designed for hardware security tokens that could securely embed the secret key that were transmitted to physical tokens or other devices.
"However, when this process was adapted for software-based 2FA apps, the secure exchange of the secret key was not properly maintained. As a result, transmitting the QR code can lead to the key being compromised. If attackers gain access to this information, they can potentially use it to bypass the 2FA protection," says Contario. "While the level of awareness of this exploit currently seems to be low – even among IT professionals – the potential for abuse exists," he adds.
Remediation Solution
To address the threat, Silent Sector has developed a fix which involves changing the enrollment process to use a QR code that is paired with a dynamic, one-time URL that directs the authenticator app to retrieve the secret key from a secure server.
"This ensures that the secret key is only sent to the authenticator app, making it more secure. To execute the fix, technology vendors and enterprises that use QR enrollment for multi-factor authentication will need to re-enroll in their 2FA processes using new, secure QR codes," explains Contario.
This way, the secret key is no longer statically embedded in the QR code, but dynamically provided to the authenticator app in a secure manner, preventing the compromise of secure data through the QR code alone.
More on Amzeal News
Deploying Remediation at Scale
The biggest remediation challenge revolves around the massive scale of the problem, the risk of exploitation once disclosed and the difficulties in properly notifying and coordinating with all the potentially affected parties.
The issue affects a large number of vendors and systems that have implemented two-factor authentication using QR codes. It is estimated that this issue could affect over a dozen common authenticator apps on the client side. On the server side, there could be hundreds of vendors that need to update their code to address the compromised data.
"There could be millions, tens of millions, or even hundreds of millions of these QR codes out in the wild, making it extremely difficult to notify all affected parties in advance. What's more, existing users who have already enrolled in 2FA using the compromised QR code process must be re-enrolled using the new, more secure process," says Contario.
Economics of Remediation
While the technical fix is not overly complex, the labor-intensive user re-enrollment process across enterprises will be a significant undertaking and involve considerable costs.
Vendors that provide the two-factor authentication software and services will have to take the lead in updating their codes to proactively address the exposure.
For end-user organizations, the major cost will be in the labor required for IT departments to notify and walk users through the process of re-enrolling in two-factor authentication.
"This is likely to be very time-consuming for large organizations and could add up to billions of dollars in enterprise expenditures globally, based on the average hourly rate for IT staff multiplied by the number of individuals that would need to be re-enrolled across many organizations," concludes Contario.
To learn more, please visit: https://datatracker.ietf.org/doc/html/draft-contario-totp-secure-enrollment or Silent Sector's page here, https://silentsector.com/2fa.
The exploit, discovered by Brian Contario, Principal Cybersecurity Architect at Silent Sector, lies in the fact that the QR codes used for 2FA enrollment contain sensitive information, including a secret key and user identifiers, which can be captured and misused if not properly secured.
"These codes have been present for over a decade, potentially affecting millions of users worldwide. While this vulnerability is not widely recognized, once it becomes more widely known, it will likely emerge as an area of focus for malicious actors," says Contario.
There are a number of ways that bad actors could gain access to the secret key information in the QR codes. Potential caches of the data include email, messaging, or cloud storage repositories where the QR codes or enrollment information have been transmitted or stored.
"Many IT shops, managed service providers (MSPs), as well as other business and technology professionals often store or email these QR codes, leaving them open to discovery. In public places, including airports, cafes and co-working spaces, images of the QR code can be captured simply by using cameras with zoom lenses when QR codes are displayed on screens for enrollment," he says.
More on Amzeal News
- The Giving Edge: Is Leveraging Outrageous Kindness the Missing Link for Corporate ROI?
- Boost Crypto Rankings Fast: Exclusive Access to Google News Sites in 36 Hours
- Bloktopia Launches New Virtual Real Estate Service: Prime Investment Opportunities in the Metaverse
- Individual Winners and Company Finalists for GCOI 2024 Announced by the Arizona Technology Council and Arizona Commerce Authority
- DTC Computer Supplies Announces Name Change to DES Technologies
Scope of the Damage
The potential scale of impact is estimated anywhere from tens to hundreds of millions of affected enrollments. Google Authenticator added support for QR codes approximately 12 years ago.
Millions upon millions of QR code enrollments enabled over the past decade have created a large pool of "data residue" where the digital fingerprints of particular 2FA interactions have been saved and archived.
The enrollment processes were originally designed for hardware security tokens that could securely embed the secret key that were transmitted to physical tokens or other devices.
"However, when this process was adapted for software-based 2FA apps, the secure exchange of the secret key was not properly maintained. As a result, transmitting the QR code can lead to the key being compromised. If attackers gain access to this information, they can potentially use it to bypass the 2FA protection," says Contario. "While the level of awareness of this exploit currently seems to be low – even among IT professionals – the potential for abuse exists," he adds.
Remediation Solution
To address the threat, Silent Sector has developed a fix which involves changing the enrollment process to use a QR code that is paired with a dynamic, one-time URL that directs the authenticator app to retrieve the secret key from a secure server.
"This ensures that the secret key is only sent to the authenticator app, making it more secure. To execute the fix, technology vendors and enterprises that use QR enrollment for multi-factor authentication will need to re-enroll in their 2FA processes using new, secure QR codes," explains Contario.
This way, the secret key is no longer statically embedded in the QR code, but dynamically provided to the authenticator app in a secure manner, preventing the compromise of secure data through the QR code alone.
More on Amzeal News
- One Of The Largest Native American Burial Sites In The United States Moves A Step Closer To National Recognition
- Transcend Engineering Announces Small Business Innovation Research Phase 2 Award from NOAA
- Cummings Graduate Institute for Behavioral Health Studies Announces New Book: Integrated Behavioral Health: Applying the Biodyne Mindset in Healthcare
- SureFlow to Showcase AI and Eco-Technology Energy Management Solutions at GITEX 2024
- Preview | Transtek Medical will participate in the HLTH exhibition
Deploying Remediation at Scale
The biggest remediation challenge revolves around the massive scale of the problem, the risk of exploitation once disclosed and the difficulties in properly notifying and coordinating with all the potentially affected parties.
The issue affects a large number of vendors and systems that have implemented two-factor authentication using QR codes. It is estimated that this issue could affect over a dozen common authenticator apps on the client side. On the server side, there could be hundreds of vendors that need to update their code to address the compromised data.
"There could be millions, tens of millions, or even hundreds of millions of these QR codes out in the wild, making it extremely difficult to notify all affected parties in advance. What's more, existing users who have already enrolled in 2FA using the compromised QR code process must be re-enrolled using the new, more secure process," says Contario.
Economics of Remediation
While the technical fix is not overly complex, the labor-intensive user re-enrollment process across enterprises will be a significant undertaking and involve considerable costs.
Vendors that provide the two-factor authentication software and services will have to take the lead in updating their codes to proactively address the exposure.
For end-user organizations, the major cost will be in the labor required for IT departments to notify and walk users through the process of re-enrolling in two-factor authentication.
"This is likely to be very time-consuming for large organizations and could add up to billions of dollars in enterprise expenditures globally, based on the average hourly rate for IT staff multiplied by the number of individuals that would need to be re-enrolled across many organizations," concludes Contario.
To learn more, please visit: https://datatracker.ietf.org/doc/html/draft-contario-totp-secure-enrollment or Silent Sector's page here, https://silentsector.com/2fa.
Source: Silent Sector
0 Comments
Latest on Amzeal News
- Secure Life App Launches: A Revolutionary Health and Safety Platform for You and Your Loved Ones
- NetverseAI and NetaverseAI By Phinge Will Be The Safest and Only Verified AI In The World
- OpsVeda Is Now Available Through AWS Marketplace
- Circumference Group Acquires Majority Stake in Visionary Integration Professionals
- Tim O'Loughlin Appointed Chief Executive Officer of Vantiva and Co-opted as a Director of the Board
- TN Nursery Gears Up for Busy Fall Shipping Season with Nationwide Fast Shipping, Low Grower Prices, and Storewide Deals
- Energy Psychology Group Announces Conclusion of Strategic Alliance with Cosmic Media
- Jazz Artist Bob Holz Signs With SoVibe Entertainment Plus Album Review In September 2024 Issue Of Downbeat Magazine
- Develop Africa Partners with Sierra Leonean Painter Sahr Songu Mbriwa to Raise Funds for Education
- Composer Andrew Prahlow to Perform Award-Winning Outer Wilds Soundtrack on Oct 17th at Brooklyn's Music Hall of Williamsburg
- CostPredict Inc. Accepted for Participation in an Exclusive Tech Venture Accelerator Program
- Human Factors and Ergonomics Society Announces 2024 Stanley Caplan User-Centered Product DesignAward
- Cell-Ed and National Minority Health Association Forge Strategic Partnership to Expand Caregiving and Health Equity Initiatives
- 8 Liner Machines deliver an entertainment experience upgrade
- Experienced International Trade and Sanctions Lawyer Jorge Vera Joins Jacobson Burton Kelley PLLC
- Fortius Metals secures $2 Million Additional Funding to Bring Advanced Metal 3D Printing to the Aerospace and Defense Industry
- Voices Rising Festival Celebrates Diversity in E. Islip, GRAMMY Governor LACHI performs!
- Cloud-Native Geospatial Forum Announces Membership Opportunities for Geospatial Professionals
- SlashNext Selected as Finalist in 2024 Top InfoSec Innovator Awards
- VSA Officially Receives SOC 2 Approval