multi-factor authentication

Social sharing site and news aggregator Flipboard has reset millions of user passwords after hackers gained access to its systems several times over a nine-month period. The company confirmed in…

Flipboard hacks prompt password resets for millions of users

Every once in a while someone will ask me what is the best security advice. The long answer is “it depends on your threat model,” which is just a fancy…

Google’s own data proves two-factor is the best defense against most account hacks

Auth0, a 2013-founded identity and authentication platform, has pushed into unicorn territory with a $1 billion valuation after raising $103 million in its latest Series E round. The round was…

Identity platform Auth0 raises $103M, pushing its valuation over $1B

Twitch has an account hacking problem. After the breach of popular browser game Town of Salem in January, some 7.8 million stolen passwords quickly became the weakest link not only…

After account hacks, Twitch streamers take security into their own hands

A stream of Chipotle customers have said their accounts have been hacked and are reporting fraudulent orders charged to their credit cards — sometimes totaling hundreds of dollars. Customers have…

Chipotle customers are saying their accounts have been hacked

Several enterprise virtual private networking apps are vulnerable to a security bug that can allow an attacker to remotely break into a company’s internal network, according to a warning issued…

Homeland Security warns of security flaws in enterprise VPN apps

Your Android phone could soon replace your hardware security key to provide two-factor authentication access to your accounts. As the company announced at its Cloud Next conference today, it has…

Google turns your Android phone into a security key

A popular WordPress plugin, installed on thousands of websites to help users share content on social media sites, left linked Twitter accounts exposed to compromise. The plugin, Social Network Tabs,…

A popular WordPress plugin leaked access tokens capable of hijacking Twitter accounts

Assuming you have your strong passwords in place and your two-factor authentication set up, you think your accounts are now safe? Think again. There’s much more to be done. You…

Cybersecurity 101: How to protect your cell phone number and why you should care

Cybersecurity 101: A second layer of security is one of the best ways to protect your online accounts from hackers.

How two-factor authentication can protect you from account hacks

A string of bugs when chained together created the perfect attack to gain access to someone’s Microsoft account — simply by tricking a user into clicking a link. Sahad Nk,…

A bug in Microsoft’s login system made it easy to hijack anyone’s Office account

Good morning! Except if you’re a hosted Microsoft customer who’s locked out of your account right now. Microsoft’s cloud-based multi-factor authentication services went down across the globe early Monday morning,…

Office 365, Azure users are locked out after a global multi-factor authentication outage

If you’d like to be sure you’re the only one posting elaborately staged yet casual selfies to your Instagram feed, there’s now a powerful new option to help you keep…

Instagram’s app-based 2FA is live now, here’s how to turn it on

Facebook has confirmed it does in fact use phone numbers that users provided it for security purposes to also target them with ads. Specifically a phone number handed over for…

Yes Facebook is using your 2FA phone number to target you with ads

Food delivery startup DoorDash has received dozens of complaints from customers who say their accounts have been hacked. Dozens of people have tweeted at @DoorDash with complaints that their accounts…

DoorDash customers say their accounts have been hacked

It’s not been a great week for cell carriers. EE was hit with two security bugs and T-Mobile admitted a data breach. Now, Sprint is the latest phone giant to admit…

Weak passwords let a hacker access internal Sprint staff portal

Let’s talk a bit about security. Most internet users around the world are pretty crap at it, but there are basic tools that companies have, and users can enable, to…

Epic Games just gave a perk for folks to turn on 2FA; every other big company should, too

A new exploit allows hackers to spoof two-factor authentication requests by sending a user to a fake login page and then stealing the username, password, and session cookie. KnowBe4 Chief…

Hacker Kevin Mitnick shows how to bypass 2FA

By now it’s crystal clear to just about everyone that the password is a weak and frankly meaningless form of authentication, yet most of us still live under the tyranny…

FIDO Alliance and W3C have a plan to kill the password

Twitter is rolling out an update to its platform security that will allow users to employ third-part authentication apps to receive a two-factor login authentication for their Twitter account. Twitter…

Twitter adds support for app-based two-factor authentication
Startups

I was hacked

At about 9pm on Tuesday, August 22 a hacker swapped his or her own SIM card with mine, presumably by calling T-Mobile. This, in turn, shut off network services to…

I was hacked

TechCrunch Disrupt alum UnifyID has the clear goal of changing the way we think about authentication. Instead of entering a username and password as the only line of defense to our…

Former Battlefield runner-up UnifyID announces $20M Series A

London-based Callsign has closed a $35 million Series A, led by Accel and early stage investor PTB Ventures, for an authentication platform which uses deep learning technology to power adaptive access…

Callsign pulls in $35M Series A for its adaptive authentication platform

We’re all pretty used to two-factor authentication now, and it isn’t much of an inconvenience to have to type in a four-digit code when you log in from a new…

Ambient noise could be your next multi-factor authentication token