Skip to main content
Epic MFAil!
To:Brew Readers
IT Brew // Morning Brew // Update
Cracks in multifactor.
April 08, 2024 View Online | Sign Up

IT Brew

It’s Monday! Remember: Your 3D glasses from Avatar 2 are not appropriate eyewear for staring at a solar eclipse.

In today’s edition:

MFA done-away

Earth to AI

🧊 Northwest Passage gets cable

—Billy Hurley, Eoin Higgins, Tom McKay, Patrick Lucas Austin

AUTHENTICATION

Multi-hacktor

Two-factor authentication is being phased out for password-free tech. D3sign/Getty Images

Multifactor authentication (MFA) is now a mandate for many regulations, cyber insurance policies, and presidential executive orders—just as attackers are finding ways to bypass it.

“It’s as though we waited to make sure that the hackers had a way around it before we decided to mandate it,” Stewart Baker, of counsel at Steptoe & Johnson LLP, said during a panel at the CISO-focused Shift Up Summit hosted in Manhattan this month, referring to MFA.

Here are some ways that attackers are getting around MFA:

  1. MFA fatigue: Threat actors pepper the targeted user with alerts to confirm authentication, hoping that, like an exhausted parent tired of “Are we there yet?” the target will accept, just to make it all stop.

An example: KrebsonSecurity reported on March 26 that some Apple customers received a plethora of push notifications, complete with Apple Support impersonators calling the individuals to say their account had been compromised and a one-time passcode required verification.

Read more here.—BH

Do you work in IT or have information about your IT department you want to share? Email [email protected].

   

FROM THE CREW

Let Morning Brew Daily make you smarter

The Crew

You’re already reading the newsletter, but did you know you can also listen to and/or watch the wittiest and smartest takes on business news?

Morning Brew Daily hosts Neal Freyman and Toby Howell have you covered on everything you need to know before your cup of coffee, from the latest headlines on the economy to explanations of viral TikTok trends.

You’ll look so smart in front of your friends.

New episodes are released every weekday at 7am ET. Check ’em out on YouTube or wherever you get your podcasts.

CYBERSECURITY

PhaaS & furious

Illustration of ChatGPT logo in a shopping bag Francis Scialabba

On April 1, comedian Jon Stewart let loose on AI, calling out the tech industry for “false promises” about the technology. And no, it wasn’t an April Fool’s joke.

The Daily Show host isn’t the only one asking questions. After over a year of relentless hype and excitement, AI is coming back down to earth. In late January, AI companies lost $190 billion in market cap after weak quarterly reports from Alphabet, Microsoft, and Advanced Micro Devices.

Value judgment. New research from The Information indicates that AI startup valuations are dropping. According to reporter Stephanie Palazzolo, AI-related startups—ones that offer large language model services—have seen investor revenue predictions drop.

“On average, investors valued these companies at 83 times their projected sales—usually calculated as annualized revenue, or 12 times their monthly revenue at the time of the investment,” Palazzolo wrote. “In comparison, three of the four AI startups that have raised money since then have done so at half of the revenue multiple of the original eight, on average.”

Read more here.—EH

Do you work in IT or have information about your IT department you want to share? Email [email protected].

   

INTERNATIONAL

The world of IT

Globe with lines symbolizing connectivity Imaginima/Getty Images

2024 may be zooming by, but IT Brew has you covered—here’s our ongoing roundup of three of the most interesting tech news stories from around the world in the last month.

Under the sea

Damage to undersea fiber-optic cables by attacks in the Red Sea have illustrated the vulnerability of international data traffic—and a project to bypass critical choke points by laying cable through the Northwest Passage is taking shape.

Politico EU reported the approximately €1 billion (or around $1.08 billion) Far North Fiber project, which will span about 9,000 miles and directly connect Alaska, Ireland, Japan, and Norway, is on track for a 2027 rollout date. The route is largely possible due to climate change, as parts of the route used to be blocked or at risk from sea ice that is now thawing.

Keep reading here.—TM

Do you work in IT or have information about your IT department you want to share? Email [email protected]. Want to go encrypted? Ask Tom for his Signal.

   

TOGETHER WITH AKAMAI

Akamai

Batten down the hatches. Get this: 29% of web attacks targeted APIs between January and December 2023. This means APIs are a focus area for cybercriminals. Fortunately, Akamai can help. They just published a report that has tons of insights and strategies on strengthening your API game. Give it a read.

PATCH NOTES

Picture of data with "Clean Me" written on it + bottle of cleaner in front of it, Patch Notes Francis Scialabba

Today’s top IT reads.

Stat: 2%. That’s the percentage of AI research dedicated to AI safety, according to Georgetown University’s Emerging Technology Observatory. (ETO)

Quote: “It is one of those moments where we have to wipe our brow and say, ‘We were really lucky with this one.’”Satnam Narang, a researcher with the cybersecurity company Tenable, referring to the discovery of sabotage in a widely used suite of compression tools (Reuters)

Read: See how human composers fared in a musical challenge against gen-AI posers. (Forbes)

Safe travels: Retrieve laptops from remote employees with Retriever—no setup fees, recurring subscriptions, or contracts required. Secure your company asset’s return trip home with the most trusted laptop return service.*

*A message from our sponsor.

SHARE THE BREW

Share IT Brew with your coworkers, acquire free Brew swag, and then make new friends as a result of your fresh Brew swag.

We’re saying we’ll give you free stuff and more friends if you share a link. One link.

Your referral count: 2

Click to Share

Or copy & paste your referral link to others:
itbrew.com/r/?kid=9ec4d467

         
ADVERTISE // CAREERS // SHOP // FAQ

Update your email preferences or unsubscribe here.
View our privacy policy here.

Copyright © 2024 Morning Brew. All rights reserved.
22 W 19th St, 4th Floor, New York, NY 10011

Top insights for IT pros

From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.

By subscribing, you accept our Terms & Privacy Policy.

A mobile phone scrolling a newsletter issue of IT Brew