Niclas Kjellin: Breaking the Next Factor – Live Multi-Factor Authentication (MFA) Hacking
About this talk
In this talk, Nicola Shelene discusses the vulnerabilities of multi-factor authentication (MFA) and highlights various hacking techniques targeting MFA systems. She explains the importance of MFA in protecting user accounts and shares alarming statistics regarding its adoption and the frequency with which users attempt to bypass it. The speaker delves into different attack methods, including SIM swapping, session hijacking, and MFA fatigue attacks, and demonstrates a live hacking scenario using a tool called Evil Jinx to illustrate how easily MFA can be compromised. By examining real-world examples, she emphasizes the need for organizations to adopt resilient security practices and educate users on the importance of maintaining strong authentication measures.
Full transcript
Thank you. Hopefully you will give me applaud afterwards as well. Um, so we're going to talk about something really cool. We're going to be hacking multiffactor. And before we do that, I'm just going to go through the boring part. So my name is Nicola Shelene. Uh, and I do a lot of things. I've been working in security for two years now. Uh, primarily working with building secure
software. Uh currently I'm part of a very small expert group that is uh looking at the security technical side of the Swedish implementation of the EU digital identity wallet. But I do lots of other things. Uh I collect passwords. I have about 7.5 billion passwords. So that's basically all your passwords. I done lots of static analysis on those or statistical analysis on those. So, I know exactly
what kind of passwords you're using and I know they're all crap. So, please after this go and change them because you can do better. Um, and I for fun I also design hacker themed stickers. So, you ever seen a sticker bombed laptop? That's kind of the things that I tend to design just for fun. So, that's me. But, we're going to talk about multiffactor today. And yes,
that we all know what we're talking about. There are three different factors that we normally speak about when you authenticate users. First one is something that you know that's your password which was poor by the way. Uh the second one is something that you have normally today. That's your smartphone or an app installed on it or an SMS sent to that phone number. And that's the one
we're going to focus on today. The third one is something that you are. That's biometrics, fingerprint, face or something similar. And we all use that because we unlock our phones with it. When you combine all these things, of course, you get better security. Um, some claims about multiffactors. This is coming from Microsoft. If you log into the Ashure and go into the configuration, I'm going to do
multiffactor configuration there. This is what they say there. 99% of all automated cyber attacks are stopped by MFA. So quite many of them. It's a bold claim, but 96% of all fishing attempts multiffactor. The problem with those numbers is that of course you're not attacking multiffactor in that case. So if you were attacking multiffactor, those numbers would be slightly different. Another thing they say is that 76%
of all targeted attacks are stopped by multiffactor. So when you go after one particular person, that's what we're going to be doing today. So we see if that holds as well talking about reality, what kind of feelings do you get when you hear multiffactor authentication? You know, if if you if I go and and tell you multiffactor can authentication. What comes up in your mind? Inconvenient. That's
a good one. And you any suggestions? Yeah. So if I hear you correctly, you're saying it's annoying. Yes. You know, not so many words, but so but most of us thinks it's annoying or if if we may think it's too complicated or too slow. This is what we feel when we go multiffactor. This is what we security people have to battle with and it's also what the
hackers are actually taking advantage of. We do not like multiffactor. We just want it over and done and that's it. And that's the little window we have to convince people to do the dirty work for us when we're them. Um, another fact from reality is that 76% or 78% uh abandon their accounts if they're forced to set up multiffactor. So if you have a service, you have
an account and all of a sudden it says now it's time to set up multiffactor. If it's not critical for you, you may as just leave it. Close to 50% of employees has tried to bypass multiffactor. So if we divide this room by half, you guys have been hacking multiffactor already. You guys haven't. But it's not really hacking. It is trying to get around it. So I
spoke to a client of mine for a couple of months ago. they're running a um a job in their CI/CD pipeline which takes quite a long time sometimes days and there's this token that this job has has got from the file server and that kind of expires sometimes during when the job is running. So the whole thing fails and it work is for nothing. So they were
asking me we need to extend that time. What should we put it at? and they're saying, "Well, we think we should put it to like forever." And I'm thinking, "Maybe that's a little bit too much. You need to rethink that because it's not good." So, the rule of thumb when you're thinking about how long should a session live is that the minimum amount of time you can
get away with, that's how long it should live. So, no one can tell you if 4 hours or 11 days or a month is correct. It's the minimum amount of time with. 10% of Microsoft and Google accounts have multiffactor. This is taking consideration all the private accounts as well. So, not a lot. If we were looking at um the business accounts as well, then about 40% or
so. So again splitting this about 50/50 you guys are using multiffactor you guys are not so you guys this talk is not for you so you can please leave now please stay it's going to be interested anyway but start using uh and this reason why we're talking about this is because of this number so close to 70% of all breaches involve some sort of non uh malicious
human element. And what is that? Well, that's some person that didn't intend to do something, click a link, help the hackers, didn't know they were helping the hackers. So, an insider which is doing just a mistake. This is why we need to understand how these things happen and what to do uh about them. And there are many different ways to hack multiffactor. I'm going to demonstrate one
of them, but I'm just going to quickly run through a couple of others. First one is uh SMS uh or SIM swapping attacks. SIM OTPs onetime password is the most common method used today to doing multiffactors. You just get the code kind of looks like this. This is from Google. You get six digits. You have to paste them in somewhere where they ask for it and you
log in. We all use this. We all seen this. It's nothing strange, but it's used everywhere. And that's the problem uh because over the past years attacks towards this has gone up to 400% increase because it's very lucrative. This is where the criminal gangs hang. Cryptocurrency sites are using this. Banks are using this and so on. In 2024, there was this person got his crypto account hijacked
and he lost $150 million. So you know here's money when you are looking into hacking uh multiffactor which you're all going to be doing after this though it's lucrative. Uh anyway uh so if you are building a system now you're thinking we should have multiffactor don't use SMS it is really bad. Use anything else but that. I'm going to show a little bit here. I'm going to
have some help demonstrating how you hack this. What is SIM swapping really? So you have to convince the telephone operator to change his phone number. uh SMS is gonna be sent to. That's really easy. And I have an assistant with me and hopefully the sound is going to uh work as well. So, in this video, which is just 30 seconds long, Jessica is going to get uh
access to this other guy who's also in the video, his email account. Uh it's 2 minutes to complete. If we watch the whole thing, she has full control of his phone number as well, but she basically does the same thing. So, just give you a taste how that works. Can we have higher? Hi. I'm actually I'm so sorry. Can you hear me? Okay. I My baby I'm
sorry. My My husband's like we're about to apply for a loan and we just had a baby and he's like get this done by today. So, I'm so sorry. I can't um call you back. I'm trying to log into our account for uses information and I can't remember what email address we use to log the account and the baby's crying and um can can you help me?
Awesome. In just 30 seconds.com, Jessica gets access to my personal email address. So, when she continues, she get access to phone number as well. Uh, and you know, if you were working for support, would Jessica? If you say no, you're lying. we all would help her, you know, because that's our job when we work at support, you know, on on the uh description of our job task,
it's going to say always help the customer. And then underneath that, there's going to be in bold capital letters, fat font, circle a couple of times, it's going to say, "Under no circumstances ever are you going to create another problem for your customer." This is why it's so easy to do these kind of attacks because they are there to help. They solved her problem. They just didn't
know why she had this problem, but they solved it. Another uh attack is called session hijacking attack. It's a little bit more complicated. This is where something gets installed on your machine and steals sessions. It's usually malware known as info stealers. And they can be distributed in many different ways. You can get an email with an attachment. You click on it. Or maybe you go to a
website and all of a sudden there's a popup coming up saying, "Oh, you have viruses on your machine. Maybe you should act quickly now to before it becomes a problem." And depending on how uh knowledgeable you are and aware of all this, you may actually do this. Or if you're in a bad situation, maybe you do it anyway. And if you do what they tell you to,
usually what happens that something crawls into your machine, gets installed and finds some goodies. When we talk about authenticated sessions, we normally talk about the browser, Chrome, Firefox, Edge, Safari, and so on. The thing is we have other apps on our machines that have equal sessions called Teams, Slack, whatever you have. So if I ask you this, how many times do you actually click on the sign
out button in teams? Do you once a day, once a week, once a month, once a year, or you ever use that button? Sign out is probably the most unused feature in Teams and Slack and all these kind of applications. We never sign out. Which means that there are authenticated sessions that last forever in these applications. We never log in either because we're not signed out. So
if you get info steelers and they steal that, they have a ticket forever to that account. So think about the next time you go on a vacation, maybe you just click on sign out. And it's actually a good thing as well because when your boss calls you saying, you know, oh, you you should have seen that. I know you're on vacation, but you should see that message.
who say well I signed up because of security reasons it's going to love you for that okay so MFA fatigue attacks is another one so imagine that you are it's early morning you know you haven't woken yet and all of a sudden your phone start buzzing and making noises and blinking and whatever it kind of looks like this you know comes all these kind of notifications one
after each other and you're like oh what's going on here I just want to deep, you know. So, you want to solve this problem. Something is not really right. So, maybe you see this kind of screen where you're going to have to select an option, you don't know which one is correct, and maybe you click cancel a couple of times and then a few more coming in
and you go like, I can't be bothered. You just select one and you keep on doing that. Statistically, you are going to get the right one after some point and that solves your problem and you can go back to sleep. you solved someone else's problem as well because you may have let someone else into your corporate uh network which happened to Uber in 2022. So this is
the actual quote from the hacker that hacked Uber. So he was using this tactic for about an hour towards an Uber employee uh who didn't actually uh accept it. So he added on another tactics called social engineering contacted this person through WhatsApp saying you know and now Uber doesn't use WhatsApp. So the so it was saying you know we are from Uber it we have a problem
with our multiffactory just stuck in a loop and keep sending these requests to everyone. So, you know, could you just click and accept it because then the problem will go away and it did and the hacker get access to the entire infrastructure of Uber including AWS services. So, there's someone that's writing for free forever now. But sometimes it looks like this. Now, I'm using Microsoft Authenticator. I
have nothing against Microsoft Authenticator. is a very good app, has good features, very common, but you get a challenge here. You need to input something. You can't really guess either. You see some number on a screen somewhere and you need to put it in there. So, when when we need to hack this, and this is what we're going to be doing. Um, we need to bring out
the big tools, you know, the big guns in order to solve this. And they're commonly known as man in the middle. Uh if we look at the screenshot in the back, this is from the dark web. If you take the dark web and you combine that with cloud, you get everything as a service. So you can buy anything there. This allows you to do MFA attacks as
a service. So you could buy a campaign towards Dropbox for about 10 days, $150 or so, or against any of Microsoft services for for a month for about $400. and it does everything for you. You just have to type a few text into a few boxes and that's it. But we're going to do it the proper way today. So, uh, we're going to take a tool that
exists. There are a couple of to choose from. So, here's a lineup. We have Merina, we had Modishka, and we have Evil Jinx. Uh, we're going to use Evil Jinx today. Here's the GitHub page for Evil Jinx. Uh, so it's just, you know, everything is there. download it, compile it, run it your machine, and hack your friends. That's the package. But we need a target. So just
imagine there's a company called Rock Paper Security and they're doing some really cool stuff and you want to have that. So you've been browsing around again, GitHub site. You see they have all these public uh repositories. they're doing good things, giving back to the community and so on, but we need someone to attack. Uh, so we look at the contributors and we see this guy, Elliot Alderson.
He seems to be working at the company. He's a platform engineer. So, Devil's people are a very good target. They have access to everything. Uh we also go to his LinkedIn page just confirm that he actually works at the company and we can see that he may have moved up the ladder. Uh he's an IT operations manager here. Maybe still working with DevOps, but this is a
prime good target, good access, but we don't have his email address. We were looking through all the public repositories, couldn't find an email address or anything. So, we go to the company's website and look at some job listings. We see one interesting thing. We has a line here where it says Angela Moss at rockpaperscurity.com. That kind of confirms what kind of format they're using. Now, this happens
to be the most common format for emails, but still we need to be sure. So, we can assume this is his email address. So, now we have somewhere to actually attack. But we need a platform to attack. So we uh may want to look a little bit further. So we go to another service do an MX tool. There are many of those. They just does a look
up towards that email service to see you know what kind of server are they using and so on. We type in the URL or the domain and we find all these indicators they are on 365. Fantastic. Now we know that. So to summarize, we have a company to attack. We have a person that we are going to use here. And we have two platforms, GitHub, and we
have Microsoft 365. So quick hands up. Who wants me to GitHub? There's a couple of you. I can see where this is going. Hands up for Microsoft 365. Yeah, couple of more. somewhere weren't really decided. So, uh, but we need a tactic. So, normally what happens is that Elliot goes directly to Microsoft 365. You know, just type in the URL and log in. That's what we all
do. What we need to do is put something middle and have him go to that site instead and then log in. But that is not going to happen automatically. So, we're going to have to send him something, a little present that he cannot refuse. And what is that? Well, going to the drawing board, we're going to write title. You know, something that catches your eye a little
bit. Write some text. What's going on? So, it kind of claims that he has ordered uh his account to be removed and that's going to happen permanently within 24 hours. A little urgency there. Okay. So that hopefully we have his attention. Now we're going to give him one more thing. We're going to give him a way out. Something that will fix this. So we put this button
in as well that says cancel account removal. Click on this. Everything will be fine. And maybe we add some logos and stuff to make it nice. So it's about that time. We're going to do this for real. And hopefully everything is going work. Um and you see what I see. That's great. So here I have an SSH connection to a virtual machine running somewhere in Europe. Doesn't
really matter Um I'm going to start in this case evil jinx here. So now it's up and running. And the little blue text you see down there that's listing fishlets. fishes are just configurations of how to deal with the data coming in from a login page from whatever platform you're attacking and what kind of things you should grab from it. So we were attacking Microsoft 365 and
I can see that oh there it is that's its internet is a bit slow. So what I need to do is I need to create a lure on the Microsoft 365 fishlets like so. That's it. And then I just need to enable that because otherwise it's not going to Okay. And we need a little URL to use. slow. And here's our fishing URL. It goes to place
as login.microsoftonline.accountreovery.io. So we'll just grab that. This is what we're going to give to Elliot. Um, and we're going to send them in a little email. So, I prepared an here where it's just an hm email. And that's the one we've been drawing up before. So, we're going to put our little lure in there. Looks good. And then we'll just copy that. And then we need a
proper client. By proper, I mean something that actually supports the features that we need. This is Thunderbird. It's a very old client. Maybe it's not as nice as most, but he has a lot of good hacking tools, so to speak. So, we want to send an email in here. We want to send it to Elliot Alderson at Rock Paper Security. We write uh final notice. And here's
where the magic happens. So we go insert HTML close to none other client does this. So this is the magic here. Insert and we have a really nice looking email. This actually made from the real emails that uh Microsoft is sending out. So we we send that it's going from Microsoft ataccountreovery.io and hopefully it's going to get away as well. So meanwhile that's happening, let's up Windows
11. Everything is a bit off the resolutions here. It's very difficult to see here, but at least you saw there was a message coming in. Um I should be able it should be able to react on now it's did okay. Um there it is. So this is the one we just sent again. It is pretty slow. And there it is. It comes from Microsoft. Uh it says
Microsoft being the sender as well. And we have our link here. So Elliot will click on that link which is not the quickest thing. Let's see. I'll do it manually. Just imagine you clicked on it. For some reason it didn't actually open. Um, it's still very very slow, but it's loading. So, there's hope. This is the problem of doing live demos is that you don't not control
of environment. And currently the internet connection here is not the best. Something is happening. You can see it says sign into your account up there is slowly moving towards if Elliot was doing this he would be calling it right now saying you know you have to do something about this internet line because we can't do our work and my account is about to close. Um Microsoft is
doing some stuff here. So, you're just seeing if you're in. And here we have a Microsoft login page, very big because I'm not controlled with resolution here right now. And Elliot will type his uh email address in there. Click next. While that's loading or what you can't see here is that the background changed because this company is running a customized background when they do login. Just so
you know you're in the place. Here's all my passwords. I'm gonna have to change them later because now they're recorded. Or I can look them up on YouTube. That's a pretty handy thing as well. So he will sign in. Everything looks okay. So while he's doing that, or maybe it's coming now, at least we can double check. If we go back here, we can actually see that
we captured something. We have his email address and his password. So, this is our little proxy just running there hijacking things. That's the man in the middle. Going back to here, he get his request. So, he has to bring up and he actually got a little notification here as well. So, you can click on that and it's going to ask for that. So, what's that? 26. So
he enters 26 and says yes. This needs a face and if everything goes through here, which is quite slow, he should be logged in in a second. And now seem to have handed it over. We'll see if that reacts at some point. It is coming. Uh while we're waiting for that. So this is just harvesting whatever it can. So really he wasn't at the Microsoft login page.
He was something that is mimicking its behavior, but he can't really tell. Um, and apparently the multiffactor isn't updating due to the internet. Let's see. Try again. As I said, this is always the worrying if you are running something live. We were working uh we're working a little bit against the time. So hopefully it's going to go through soon or you're just going to have to take
my word for it and which is really crap. But we'll see. We'll give it another shot. We'll click this link. Hopefully it's going to be a little bit more cash this time. But what you're going to do while we're waiting for that is you're going to give me a huge amount of applaud because I password. Thank you. Gives me a little energy. I'm pretty sure we're going
to just have to leave it here. But what's going to happen, I'm going to explain to you what's going to happen is that if we go back here, so we just leave that in the background and we look. But this is extremely slow. So this I am unsure this is going to go go through. Already types a lot here. Let's see when that goes through. I'm the
slowest typer in the world, but I can type away from my P uh keyboard, impressive. So, here we can see there is this session that has been established. This is what Elliot did when he logged in with his username and password. And once we he actually approves the multiffactor, the the little thing that says token says none would have had a value in it. And then we
can take that value. Just going to see how it's going here. Okay. So, maybe maybe we're getting a little bit closer. So, let's try a final time. Now, we have here and we're going to hope everything It did something. I think that's enough. back, we actually see the um No, it didn't. I think it it hasn't gone through. It needs to load. There's another little Yeah, this
one. Let's say yes on that. Microsoft doesn't do make it easy you and we pay them a lot of money. But look, all authorization tokens intercepted. So slowly we're getting there. Now we have something captured in token. So what's that? That's session 11. Again, I'm doing my magic typing. So as soon as that go through, we may have something fun. At least we have a few more
minutes. How are we doing on time? You guys don't have any questions anyway, so we can run through that. Okay, so here we have something captured. So I'm going to make it complicated though. Um, I do have another machine running here, running Linux, Kali Linux to be precise, but doesn't really matter. It's just a different machine. So, pretend this is the hacker's machine. So, he's going to
go to Outlook. Um, that's a lot of loading here all the time. So, he's going to go there and uh see what he can do with it. So, meanwhile that's loading, we could go back and we need this little here. What this line includes is a lot of cookies. It's a great screen. Um, what what what do you guys want to do that I try to complete
the actual live element or I'm just going to summarize and you can see what happened? that kind of takes on the time of the presentation itself. But I'm happy to just wait around because now it's loading. I will skip everything else because this is the interesting part. So now it's just I'm going directly to Outlook. It shouldn't actually be logged in. Microsoft should realize that and goes
over to you can hardly read that it says logging.microsoft uhonline.com. It's going to do some loading here. [Music] And it's actually putting something up. So, we're not logged in. Surprise. And it it wants us to log in. But the thing we don't really want to log in, but here's a lot of cookies that we sent, but we're just going to scrap those. That's all Microsoft just put
because we went there. And we go into import and we just paste that string that we got and do import that. And it says a couple of different cookies. And now internet isn't the quickest, but let's do reload and see what happens. So imagine this is completely different machine. It could be anywhere in the world. Doesn't really matter. Now it just happened to run on my computer
because it's a little bit easier. Um but the problem is of course that internet's a bit slow. It is still loading. It's doing a lot of stuff. Or was it? Now it's loading. Yeah, it's talking to lots of things down there at the very least. And now it's doing something. Okay, we're getting uh Does it look good? Let's see. But hang on, it found an account. Elliot
Looks good. We click on it. Okay. So, where are we going now? I really hate that envelope Oh, we have Outlook there. It becomes a lot better when it goes smooth. But now we actually have the same this is the same authenticated session but running in Linux on another machine. If we wanted pointed to a VPN somewhere else, we could have done that but I think that
would make everything worse right now with internet connection. So the the thing is that this is not really how you do it normally. You have a better internet connection now but you don't do it manually. This is for show. You know, why sit around and wait for Elliot to do things when you can watch Netflix and have automated tools? Doesn't have to be too complicated. Now, I'm
not sure how they worked, but they have had a few minutes. So, I have another tab here where down there is running auto exfiltrate Python script and it says monitoring capture capture session. is looking at you know all these capture sessions if there's going to be something coming in and as soon as there is something they'll do whatever in this case it downloaded file from Microsoft 365
um you may not have seen them because everything was slow but it has created now a folder there 25 20 25 something and inside that there were a couple of files. No, I actually go into it. Like so. And these three PDF files it did actually download. And you can see what's the time now? It's it's about uh 6 minutes ago. This happened the second that Elliot
approved the multiffactor. So even if he would have at that point realized I'm being tricked, it is too late. And this is really how it works today is that no one sits around wait for you to do things. They are sitting there with a script watching Netflix, eating popcorn and just check this every so often and that's everything. If we were had GitHub, guess what it would
have done? Would cloned those repositories that were private for that account. also done the second they were approved the GitHub multiffactor. We don't have that much left. Um so now I'm just giving away everything. So anyway, so these are the two different ones that he would have seen. Oh no, not this the left one. That's what I gave away. I have two minutes left. So this is
fake. Anyone see any difference now? It's a bit fuzzy. any difference to them except for the big fake sign. It is really the URL but again who knows what Microsoft using so many long ones. So the real one is login microsoftonline.com whereas this one has accountreover.io at the end. But if you don't know that, how would you know? Because there's no difference. It is the exact same
page just running through proxy. Um so we're going to skip the GitHub one of course. And if I have a pound. So let's go to this one. I have you just wrap this up now. So what do you do to protect yourself? Well, you can use more resilient methods. Pass keys coming up. That that's uh Microsoft, Apple, Google, a few more uh project you have them already
in your mobile phones maybe using somewhere. That's like having walking around with cryptographic device that proves who you are or more prove that you have that phone. um they can be hacked as well but not through this method. Um use MFA appropriately. Normally we put it where you log in and that's it. Start moving them to where the sensitive operations are because then you're going to have
to hack that person twice which is a little complicated and use device- based security. Microsoft calls this conditional access goes by many names. Uh if you think it from a user perspective, imagine you were annoyed by all the multiffactor. Imagine you can just click trust this device and you will never ever see multiffactor again. That's actually the best thing for security you can do because the user
is happy and security is good. You trust that device now. And then you can tell the user, okay, the next time you see multiffactor on that trusted device, something is wrong. Let us know. Uh monitor your system. I had this uh client once uh that they invested so much money in everything firewalls, IDPs, ID, ids and so on so on. A lot of money generating billions of
log entries every second almost. Uh but they missed one thing. No one was watching the logs. So it's completely waste of money because they didn't know what's going on. So you need to understand that you need to look at what's going on in your system. So if you see that there are multiple MFA requests or fails then they're coming directly after each other that could be uh
MFA fatigue attack happening. And we also need to educate our users. Most important thing to do let them know why they need to do things. Don't just tell them they need to do things. Let them know why it's good. And finally, just so you didn't misunderstand me, always use multiffactor when it's available. It is the best thing. It's not flawless. Uh, and don't get lazy with your
passwords. People tend to do this when you get multiffactor. I have a thank you here. Uh, and finally, don't trust those domains. If you click on a on a button that was sent to you, check what the are. Uh, and I do have stickers. So, once this over, anyone who wants stickers could come down and get some. But, um, thank you so much for having me. and
though it was a bit slow uh and enjoyed the rest of your conference. Thank you very much. I think we have a time for a couple of questions. Yep. Sure. I thought I was out of time. We have three minutes. Three minutes. That's plenty. Okay. So, majority of risk is in social aspect. What are the best methods to educate people without bothering too much? No one likes
awareness training, you know. Um, the thing is there are probably no good a way of doing it. You can hack them and that's, you know, that's that's cool, but I don't know if they would appreciate that, but at least they learned something. But the thing is, it's a difference between telling people what to do and telling why they need to do things. So if you want someone
to actually help you in security from a user perspective, they need to know why they are having multiffactor and why they need to answer these things because it is it is annoying but if I'm aware that it protects my data or something, I'm probably more likely to actually accept it. So it's the why we're missing. Why do we have this security? Um, good demonstration of a regular
fishing attack, but how do you prevent it? What client and server side solution are there? Um, yeah, it's a good question. Um, Pasi is one of those that you could use, but of course very hasn't been used so much. Um, the problem is that there is no good way of preventing this uh because you have to clust trust the client in this case. So if you're building
the login page, the login page can look at the domain and it can realize that this domain is wrong and then it could do something. The problem this is it becomes a cat cat and mouse race because then of course we're updating the tools to rewrite the the client side to not look at the domain and so on so on. So there are no good ways to
protect from this. No no 100% sure ways. Sorry. UB key. Yes. But then we're going to pass key kind of. So then you have to bring in particular if you're using UB key, then you're not going to be happy among your users. You know, here's a little plastic thing you're going to have to carry around and stick into your machine every time you're going to log in.
Goes down not so well usually, but it's actually very good security. Okay, maybe first one. Do you think that allowing remote SSH access to the root account over a public IP as you demonstrated is a good practice from a security perspective? [Laughter] Yeah. Well, um, no, don't do what I did. Um, this wasn't a demonstration, so you don't learn from me from that perspective. No, it's never
good. You should never use root for anything really. you know, you should forget that exists. Actually, I think um um what's what's her name? Um uh can canonical Linux system they're moving away from from the pseudo aspect even. So, they're going to introduce something else. U was the word I was looking for. So, this is a problem. We are allowing too much privileges to accounts that we're
using daily and usually those accounts are called admin and is shared by all people. Don't do that. Don't do what I did. Um so so it's never a good uh idea. It was his question. I can see well last one. Okay. In addition to session theft, what about Microsoft notifying you if you're logged in from different locations around the world? Yeah, I I think there is a
lot of configuration you can do on Microsoft. Now, if I would have done that here, they wouldn't notified me. So, it doesn't really matter from most user perspective. So, it really uh if you go to conditional access uh rules that you can set up, yes, you can do all this kind of cool stuff and you should probably do that if you have that need. it does also
maybe provide frictions from the user. So it's always a balance. Uh but normally they don't actually and the reason for that is that they need to consider that IP addresses are changes all the time. If you're on the phone network which I was now just trying to get these things through the IP is changing constantly. So you can't really rely on it. But sure if someone is
here in Vius and then two minutes later they're in Bangkok may not be completely correct, you know. So yes, you can use as an indicator, but it's it's very dangerous to use it as as like a hard rule. Thank you. Thank you very much. [Applause]