Blog
One extra step instead of cutting corners
By Didier Battermann

Before you read on: this is not a trendy healthy lifestyle blog, but an essential step for your security. These days, an ever larger part of our lives takes place on mobile devices and computers, both privately and at work. As a result, digital accounts have become a target for criminals. That your data is valuable is clear from the worrying rise in cyberattacks on governments, businesses and private users. So it is important to secure your data as well as you possibly can. A handy yet highly effective way to do this is to use two-factor authentication, or 2FA.
What exactly is 2FA?
Two-factor authentication is an extra layer of security that ensures people cannot simply gain access to accounts, hardware, software and other things. As usual, a user first enters their login details. But instead of getting straight into the data, they are asked for an additional authentication through another medium. Think of a temporary verification code sent to the known user by email, text message or push notification. In this way, 2FA acts as a password manager that offers better protection against threats and intrusions. Entering the standard login details of a username and password is therefore no longer enough, because the temporary code is only sent to an authorised user and device.
In practice, a great many applications already support 2FA. Wherever it is available, you should use it. It is an easy way to take a very effective measure for your security.
Different types of 2FA
If an application only requires a username and password, there is a good chance that a data leak will happen at some point. That is why 2FA should be used on top of the first verification method. But within 2FA there are still differences in the strength and complexity of the security. As you read above, there are several types of two-factor authentication:
- One-time password token. This provides a one-off code that is only valid for a short time.
- Text message with a verification code sent to your personal mobile device, such as your iPhone, Samsung or Google Pixel phone.
- A dedicated authenticator app such as Google Authenticator or Authy
- Hardware token in the form of a USB stick or key fob. It generates a new code every 30 seconds that you can use to log in.
Good but not perfect
Two-factor authentication is a very effective measure for securing your data. But it is not 100% watertight. Like every other security solution, 2FA can be bypassed by cybercriminals. It is just much harder than when you only use a username and password.
To still gain access to your data, an attacker either has to get hold of the hardware token or, in the case of software applications, gain access to the tokens generated on the device. This happens in the following ways:
Social engineering/Phishing:
The biggest weaknesses in any security system are still the people who work with it. Social engineering and phishing exploit this human factor. By email or over the phone, cybercriminals pose as a trustworthy person in order to obtain confidential information that lets them bypass 2FA.
Malware
Malicious software can be used in various ways to extract the token from a device. Keylogging malware records keystrokes and can pass the token on to the attacker that way.
Would you like advice on using 2FA, or do you have other questions about Cybersecurity? Feel free to contact us, without obligation!
Wondering what Infodatek can do for you?
A thirty-minute call with one of our specialists. Your environment, your questions. An honest conversation.
