DEV Community

Serguey Shinder
Serguey Shinder

Posted on

They Did Not Break Our Second Factor, They Rang the Service Desk

The attempt that succeeded against us never touched the second factor. A man phoned our service desk at half past four on a Friday, said he was a regional sales manager, explained that he had a new handset and had lost his authenticator, and mentioned that a customer was waiting on a quotation. The analyst reset the factor, talked him through enrolling a new device, and closed the ticket in six minutes with a satisfaction score of five.

Every part of that interaction met our standard. The analyst followed the script we wrote for him. He confirmed a date of birth and the last four digits of a mobile number, both of which can be bought, and the caller knew the manager's name, his role and his customer, all of which sit on a public professional profile.

We had spent a year and a considerable sum making authentication strong, then left the one route that bypasses authentication entirely in the hands of a team whose performance is measured on how quickly they can be helpful.

What made it worse was uniformity. The same desk performs recovery for a warehouse operative and for a finance director who can release payments, using identical questions, in the same six minutes.

We changed the process rather than the staff, because the staff did what we instructed. A factor reset on any account with privileged or financial access now requires a callback to the number held in the human resources record rather than the one the caller offers, plus written confirmation from the line manager. Ordinary resets moved to a self-service flow using a code sent to an already enrolled device, so most of them never reach a person. Where a person is involved, identity is checked against something the caller did not get to choose, and the analyst has explicit written permission to refuse, with a named manager to escalate to when somebody senior becomes irritated.

That final clause did most of the work. We had never actually told the desk that no was an available answer.

Our awareness material promises that the service desk will never ask you for your password. It says nothing at all about what the service desk might hand over.

– Serguey Shinder

Top comments (0)