It's not. Allow SMS to be disabled in favor of a more secure option (WebAuthn). Strongly suggest that users purchase a token.
It's not. Allow SMS to be disabled in favor of a more secure option (WebAuthn). Strongly suggest that users purchase a token.
Although they’re not popular in security circled because technically they’re still vulnerable to phishing websites, I prefer TOTP apps like Google authenticator because it’s backed up to the cloud so even if I lose my phone I know I can get back the keys; it’s the best trade off for security vs usability.
It seems reasonable to me to require employees to use a physical authenticator. Heck, how many of the people here use them and require employees to use them? Often to secure access to applications and resources less consequential than Official Acts Of The Federal Government.
It would feel less reasonable (and a throwback to the ‘00s) to mail out hardware authenticators to customers/members of the public just to, say, buy stamps from the USPS or something.
But the employee needs to be responsible enough not to lose it, they definitely need to not be able to back it up to god-knows-what consumer-grade provider (or to duplicate it at all). And when they lose it, IT needs to know to invalidate the lost one and issue them a new one.
My impression is that physical authenticators (often in the form of smart cards that double as employee ID) are pretty much table stakes in serious federal environments anyway, is that mistaken?
Ah, the never-ending circle of life.
I'm a Federal contractor. At least for my agency this is table stakes for any application period. I don't even have a password anymore. For the very small number of legacy applications that don't support smart card auth I have to log in to a different service to get a temporary password that expires after 24 hours.
There is nobody that is unphishable. Very competent, careful, highly-skilled employees can be and have been phished.