Tag

Authentication

All articles tagged with #authentication

Google Strengthens Android Theft Protections With Stronger Auth and Remote Lock
technology27 days ago

Google Strengthens Android Theft Protections With Stronger Auth and Remote Lock

Google rolled out stronger Android theft protections, including a configurable Failed Authentication Lock, expanded Identity Check to require biometric verification for actions outside trusted locations and to cover all Android Biometric Prompt apps, improvements to prevent accidental lockouts, longer lockout times after failed attempts, and a Remote Lock with an optional ownership verification step. In Brazil, new devices will have Theft Detection Lock and Remote Lock enabled by default. Recovery tools now work on Android 10+ and safeguards on Android 16+, with Android in-call scam protection extended to major banks and Cash App/JPMorgan Chase in the US.

SMS sign-in links expose data for millions, study warns
technology1 month ago

SMS sign-in links expose data for millions, study warns

A new study finds that many services authenticate users via SMS-delivered links or codes, with weak, easily guessable tokens that can be brute-forced or enumerated to access other users’ accounts and view sensitive data. Researchers analyzed 332,000 unique SMS URLs from 33 million texts across 177 services, uncovering 701 endpoints that exposed data and 125 allowing mass enumeration. Only a minority of providers contacted by the researchers have fixed the flaws, underscoring the need for stronger authentication, time-limited links, and multi-factor checks or safer alternatives like email-based magic links.

The Shift Toward Passwordless Security: Embracing Passkeys and Facial Recognition
technology1 month ago

The Shift Toward Passwordless Security: Embracing Passkeys and Facial Recognition

Passkeys are a secure and user-friendly alternative to passwords that are underutilized due to low awareness, misconceptions, and implementation challenges. Companies are encouraged to promote phased adoption and educate users on their benefits to improve security and user experience, especially as traditional methods become more vulnerable to AI-driven attacks.

Plex Security Breach Prompts Urgent Password Changes
technology5 months ago

Plex Security Breach Prompts Urgent Password Changes

Plex has warned users to reset their passwords following a data breach that exposed email addresses, usernames, and securely hashed passwords. The company has addressed the breach and recommends users change passwords, log out of all devices, and enable two-factor authentication for added security. No payment card information was compromised in the incident.

Buyer Scores £30,000 Salvador Dalí Painting for Just £150 at House Sale
art7 months ago

Buyer Scores £30,000 Salvador Dalí Painting for Just £150 at House Sale

A modestly priced painting bought for £150 at a house clearance sale in Cambridge has been authenticated as a genuine Salvador Dalí artwork, valued at £20,000 to £30,000. The piece, Vecchio Sultano, is part of Dalí's unfinished Middle Eastern folktale illustrations, which were largely unpublished and stored in a London garage. The discovery highlights the potential value hidden in overlooked art pieces and the importance of expert authentication.

Facebook and Meta Launch Passkey Support for Enhanced Security
technology8 months ago

Facebook and Meta Launch Passkey Support for Enhanced Security

Facebook now supports passkeys, a secure and convenient authentication method that replaces passwords with device-based verification like face or fingerprint scans, enhancing account security and reducing phishing risks. The feature will roll out to iOS and Android soon, allowing users to use passkeys for Facebook login, Messenger, and Meta Pay, and is part of a broader industry move towards more secure login methods. Users are encouraged to set up passkeys and ensure their passwords are strong and unique, with two-factor authentication as an additional safeguard.

Facebook Launches Passkeys for Enhanced Account Security
technology8 months ago

Facebook Launches Passkeys for Enhanced Account Security

Facebook is adding support for passkeys on its mobile app, allowing users to log in using device authentication methods like fingerprint or face scan, which enhances security and helps prevent phishing attacks. The feature will be available soon on Android and iOS, and will also support Facebook Messenger, joining other major platforms like Google, Apple, and Microsoft that have adopted passkeys. Users can still use passwords or other authentication methods, and passkeys are built on WebAuthn technology, offering a more secure alternative to traditional passwords.

Hackers Exploit Check Point VPNs to Infiltrate Networks
cybersecurity1 year ago

Hackers Exploit Check Point VPNs to Infiltrate Networks

Hackers are targeting Check Point Remote Access VPN devices to breach enterprise networks by exploiting old local accounts with insecure password-only authentication. Check Point advises customers to enhance security by using certificate authentication or deleting vulnerable accounts. A hotfix has been released to block weak password-only authentication. This follows similar attacks on Cisco VPN devices, highlighting a broader trend of VPN-targeted cyber threats.

"Google Wallet Implements Rapid 'Verify It's You' Request Feature"
technology1 year ago

"Google Wallet Implements Rapid 'Verify It's You' Request Feature"

Google Wallet is reportedly testing a new feature that requires users to re-authenticate for tap-to-pay transactions, even for small amounts, within a few minutes of unlocking their device. This change is observed on the Pixel 8, prompting users to verify their identity three minutes after unlocking via fingerprint. The prompt did not appear on other Pixel phones, indicating that Google may still be testing or gradually rolling out this behavior. This move aligns Google Wallet closer to Apple Pay's authentication process for every tap-to-pay transaction.

"Google's Chrome Enhancements Combat Cookie Theft and Hijacking"
technology1 year ago

"Google's Chrome Enhancements Combat Cookie Theft and Hijacking"

Google is developing a new web capability called Device Bound Session Credentials (DBSC) to combat cookie theft by tying authentication sessions to a specific device using cryptographic keys. This aims to disrupt the cookie theft industry and reduce the success rate of cookie theft malware. The DBSC API allows a web server to associate a session with a public key generated by the browser, and Google expects the Chrome browser to initially support DBSC for roughly half of desktop users. The company is also working to make DBSC an open web standard and is experimenting with using the tech to protect some Google Account users running Chrome Beta.