FB pixel

Okta report on credential stuffing attacks marks another blow against passwords

Automation, availability of stolen login credentials fuel attacks mirroring Cisco assault
Categories Access Control  |  Biometrics News
Okta report on credential stuffing attacks marks another blow against passwords
 

San Francisco’s Okta says a wave of credential stuffing attacks that is “unprecedented” in scale uses the same infrastructure as attacks on Cisco’s VPN services earlier in April. The trend is sure to reignite discussion about the dubious security of passwords and potential alternatives that use security keys or biometric authentication.

A post on the company’s blog, entitled “How to Block Residential Proxies using Okta,” says that “over the last month, Okta has observed an increase in the frequency and scale of credential stuffing attacks targeting online services, facilitated by the broad availability of residential proxy services, lists of previously stolen credentials (‘combo lists’), and scripting tools.” In credential stuffing attacks, bad actors with access to large lists of names and passwords obtained from data breaches use automation to try hundreds of login combinations in minutes.

Both recent rounds of attacks were deployed through and made possible by anonymizing services, notably TOR. “Millions of the requests were also routed through a variety of residential proxies,” says Okta’s post. Residential proxies route IP data and authentication requests through a network of legitimate user devices, such as smartphones or routers, to anonymize them. Some users are aware their devices are being used as proxies, but others have had malware enroll devices in proxy networks without their knowing.

Okta says users should keep defense software up to date. “The unprecedented scale of these attacks has provided clear insights into the controls most effective against credential stuffing.

ThreatInsight, Okta’s built-in control against high volume attacks, blocks requests from IPs involved in large scale credential based attacks prior to authentication.”

In its recommendations, it encourages customers to embrace passwordless, require Okta FastPass and FIDO2 WebAuthn, and support passkeys as a preferred sign-in method.

Cisco’s parent company, Duo Security, recently migrated its membership in the FIDO Alliance to Cisco and joined the FIDO board. Cisco has been reorienting its security strategy around identity and AI to strengthen its defensive posture.

Industries across the board are following suit, with the auto industry showing particular enthusiasm for passwordless authentication. Data breaches keep happening, and fraudsters are getting better at using increasingly advanced tools. Passwords have hung on for longer than some expected. But if the current wave of credential stuffing attacks keeps swelling, expect password-based authentication to be subsumed soon enough.

Technical details on the attack can be found at the bottom of Okta’s post.

Related Posts

Article Topics

 |   |   |   | 

Latest Biometrics News

 

As identity infrastructure scales, governance becomes the differentiator

Biometrics bound to credentials increasingly underpin the trust infrastructure of digital life, yet as digital systems reach deployment, they are…

 

Imprivata CEO tells Biometric Update Podcast why identity must evolve faster

A lot of people will tell you how fast the tech industry moves. Fran Rosch, the CEO of Imprivata, has…

 

Passenger growth, AI fraud push digital travel credentials toward tipping point

Digital travel credentials (DTCs) are at a crucial moment in their adoption as the travel industry undergoes profound structural changes,…

 

Thales makes strong debut in NIST’s FRIF fingerprint biometrics benchmark

New entries to NIST’s benchmark for large-scale fingerprint biometric capture and comparison software from Thales and Innovatrics show significant gains…

 

CCIA entreats US Supreme Court to intervene in Texas app store age check law

In the present historical moment, it is borderline comical to see advocacy groups for the technology industry insist that age…

 

The US counter-cartel fight is becoming an identity intelligence war

The creation of the Joint Interagency Task Force-Counter Cartel (JIATF-CC) under the U.S. Northern Command (NORTHCOM) marks more than another…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events