FB pixel

Legacy MFA methods common for new device logins: Incognia app friction report

Legacy MFA methods common for new device logins: Incognia app friction report
 

A review from Incognia of the friction experienced when users attempt to login to mobile apps with a new device indicates that only a couple of apps provide authentication from a new device without adding substantially to the time and difficulty of the process. Deprecated multi-factor authentication (MFA) techniques appear to be significantly more common than biometrics use.

The ‘Device Change Mobile App Friction Report’ for 2021 examines 24 leading mobile apps for fintechs and banks, to understand how authentication methods are used to protect logins from new mobile devices.

Account takeover attacks made up over half of all fraudulent transactions in 2020, so financial institutions are motivated to make sure they have high assurance that their users are who they say they are. Financial institutions are therefore on guard against social engineering, SMS phishing (or Smishing), and SIM swaps when an unknown device attempts to access an existing account, Incognia explains.

The study shows an average of 53 seconds to complete authentication on a new device. Three quarters of the apps tested support one-time passwords (OTP) over SMS for authentication, despite NIST deprecating the method in its SP 800-63B Digital Identity Guidelines last year for being insufficiently secure.

MFA based on a knowledge factor and a possession factor does not necessarily help, according to the study. Nine of the 24 apps support a 4-digit PIN for authenticating mobile devices, which Incognia found adds significant friction.

Two of the apps, those from E-Trade and Klover, were found to allow authentication on a new device with no visible extra step, and consequently provided authentication from new devices with the lowest friction. Incognia speculates they may be using behavioral biometrics or another passive authentication method.

Incognia has also published a Mobile App Friction Report for login authentication and password resets to analyze the use of passwords and passwordless login technologies, support for MFA among financial apps, and compare the amount of friction found in different apps.

“Most account takeover attacks are now a result of social engineering, phishing and SIM swaps but still, most Apps are using SMS as part of their device authorization process, which is highly vulnerable to these attacks,” comments André Ferraz, founder and CEO of Incognia. “Smartphones today contain technologies and sensors that can be leveraged for frictionless adaptive authentication, reducing the risk of ATO without adding friction to the user experience.”

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Opinions on UK Online Safety Act emphasize importance of enforcement

Online safety legislation is making headlines around the world. But in places where laws have taken effect, are they proving…

 

UK Home Office raises estimate for passport contract to 12 years, £576M

The UK Home Office has opened a third round of market engagement for its next major passport manufacturing and personalization…

 

US lawmakers move to restrict AI chatbots used by kids

A bipartisan pair of House and Senate bills would impose new federal restrictions on AI chatbots, including a ban on…

 

Utah age assurance law for VPN users takes effect this week

Privacy advocates and virtual private network (VPN) providers are up in arms over Utah’s Senate Bill 73 (SB 73), “Online…

 

CLR Labs wins ISO 17025 accreditation for biometrics testing across EU

Cabinet Louis Reynaud (CLR Labs) has been accredited for ISO/IEC 17025, the international standard for testing and calibration laboratories, in…

 

Leidos, Idemia PS advance checkpoint modernization with biometrics, CAT-2 systems

Leidos and Idemia Public Security have formed a strategic partnership to deploy biometric‑enabled eGates and integrated Credential Authentication Technology (CAT-2)…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events