* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Friday, May 23, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Embracer intends to spin off Coffee Stain Group by the end of 2025, with remaining business rebranded as Fellowship Entertainment – GamesIndustry.biz

    Embracer intends to spin off Coffee Stain Group by the end of 2025, with remaining business rebranded as Fellowship Entertainment – GamesIndustry.biz

    San Jose eyes creation of entertainments zones with FIFA World Cup, Super Bowl LX on the horizon – The Mercury News

    San Jose Sets Its Sights on Exciting Entertainment Zones Ahead of FIFA World Cup and Super Bowl LX!

    Wilmington’s future of fun: 5 recreation and entertainment spaces planned in the Port City – Wilmington Star-News

    Exciting Developments Ahead: 5 New Recreation and Entertainment Spaces Coming to Wilmington!

    Jason Momoa Is Done With Peace in Apple’s ‘Chief of War’ Teaser – Yahoo

    Jason Momoa Embraces Chaos in Gripping Teaser for Apple’s ‘Chief of War’

    AI Entertainment Studio Promise Inks Deal With Google, Raises Investment from Michael Ovitz’s Crossbeam – The Hollywood Reporter

    AI Entertainment Studio Promise Secures Major Deal with Google and Attracts Investment from Michael Ovitz’s Crossbeam!

    Jennifer Lawrence and Robert Pattinson Did This “Humiliating” Thing to Prep for Sex Scenes – Yahoo

    Jennifer Lawrence and Robert Pattinson’s Hilarious Preparation for Steamy Sex Scenes!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Aera Technology Debuts Decision Intelligence Skill to Navigate Shifting Tariff Dynamics Across Value Chains – Silicon Canals

    Unlocking Success: Aera Technology Launches Innovative Decision Intelligence Skill to Tackle Evolving Tariff Challenges in Value Chains

    Auditory Processing and Psychosocial Improvements with Remote Microphone Technology: An Evidence Review – The Hearing Review

    Unlocking Sound: How Remote Microphone Technology Enhances Auditory Processing and Boosts Psychosocial Well-Being

    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Novotech Honored with Triple Win in 2025 Pharmaceutical Technology Excellence Awards – Morningstar

    Novotech Celebrates Triple Triumph at the 2025 Pharmaceutical Technology Excellence Awards!

    Experts Issue Warning on New TSA Technology – Men’s Journal

    Experts Sound Alarm Over New TSA Technology: What You Need to Know

    Cellino’s iPSC Manufacturing Technology Receives FDA Advanced Manufacturing Technology (AMT) Designation – Business Wire

    Cellino’s Groundbreaking iPSC Manufacturing Technology Earns FDA’s Advanced Manufacturing Designation!

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Embracer intends to spin off Coffee Stain Group by the end of 2025, with remaining business rebranded as Fellowship Entertainment – GamesIndustry.biz

    Embracer intends to spin off Coffee Stain Group by the end of 2025, with remaining business rebranded as Fellowship Entertainment – GamesIndustry.biz

    San Jose eyes creation of entertainments zones with FIFA World Cup, Super Bowl LX on the horizon – The Mercury News

    San Jose Sets Its Sights on Exciting Entertainment Zones Ahead of FIFA World Cup and Super Bowl LX!

    Wilmington’s future of fun: 5 recreation and entertainment spaces planned in the Port City – Wilmington Star-News

    Exciting Developments Ahead: 5 New Recreation and Entertainment Spaces Coming to Wilmington!

    Jason Momoa Is Done With Peace in Apple’s ‘Chief of War’ Teaser – Yahoo

    Jason Momoa Embraces Chaos in Gripping Teaser for Apple’s ‘Chief of War’

    AI Entertainment Studio Promise Inks Deal With Google, Raises Investment from Michael Ovitz’s Crossbeam – The Hollywood Reporter

    AI Entertainment Studio Promise Secures Major Deal with Google and Attracts Investment from Michael Ovitz’s Crossbeam!

    Jennifer Lawrence and Robert Pattinson Did This “Humiliating” Thing to Prep for Sex Scenes – Yahoo

    Jennifer Lawrence and Robert Pattinson’s Hilarious Preparation for Steamy Sex Scenes!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Aera Technology Debuts Decision Intelligence Skill to Navigate Shifting Tariff Dynamics Across Value Chains – Silicon Canals

    Unlocking Success: Aera Technology Launches Innovative Decision Intelligence Skill to Tackle Evolving Tariff Challenges in Value Chains

    Auditory Processing and Psychosocial Improvements with Remote Microphone Technology: An Evidence Review – The Hearing Review

    Unlocking Sound: How Remote Microphone Technology Enhances Auditory Processing and Boosts Psychosocial Well-Being

    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Quadient and Nuvei Forge Strategic Technology Partnership – Finovate

    Novotech Honored with Triple Win in 2025 Pharmaceutical Technology Excellence Awards – Morningstar

    Novotech Celebrates Triple Triumph at the 2025 Pharmaceutical Technology Excellence Awards!

    Experts Issue Warning on New TSA Technology – Men’s Journal

    Experts Sound Alarm Over New TSA Technology: What You Need to Know

    Cellino’s iPSC Manufacturing Technology Receives FDA Advanced Manufacturing Technology (AMT) Designation – Business Wire

    Cellino’s Groundbreaking iPSC Manufacturing Technology Earns FDA’s Advanced Manufacturing Designation!

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Business

Addressing the insecurity of verified identities

October 22, 2023
in Business
Addressing the insecurity of verified identities
Share on FacebookShare on Twitter

Cybersecurity has been identity-centric since the first username and password appeared. During the infancy of personal computers, user identification was considerably simpler. At that time, workplace technology was physically confined to an office and the business network (if one existed). The only people with access were employees and maybe office cleaning staff.

The locked office door separated business assets from the rest of the world, making it the unsung cybersecurity hero in this early era. Today, we can’t rely on deadbolts to do the heavy lifting for enterprise security. The number of people with potential access to our business systems extends beyond the office and encircles the globe. Technological advancements, including the internet, cloud computing, and 5G connectivity have made user/password identification obsolete. We’re regularly connected with billions of people, some who harbor ill intent.

Do more of the same?

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.

Please enter a valid email address

Security practitioners doubled down on ID checks to address  increased exposure to the masses. After all, asking one question (password) worked when systems were accessible to just a few people. Maybe asking more questions would work to verify individuals among many people.You have a password – do you also have an RSA token with a secret number on it? Do you have a recognized fingerprint? Do you have a smartphone to receive an access code? How about three personalized security questions with three specific answers only you know?

Each new step in these identification efforts introduced friction into people’s workflow. Typing a password is fast. Obtaining numbers from multiple devices, less so. Each additional identity check presents a roadblock between the user and the work they are trying to do. Sure, each step also adds another level of confidence to the verification process, but this approach is not scalable. For example, if you’re asked to fill out the US government’s Questionnaire for National Security Positions, you’ll find it is 136 pages long. That’s a great approach for exhaustively verifying an identity, but far too cumbersome for logging into a workstation.

To make matters worse, it turns out that adding multiple layers of identity checks doesn’t stop bad actors from gaining unauthorized access. Many of today’s most popular forms of identity verification, such as multi-factor authentication (MFA), are hackable. I’m not suggesting we let perfect be the enemy of good. I’m simply pointing out that our best identification efforts aren’t bulletproof, and this knowledge brings with it a new set of responsibilities. If outsiders can outsmart our initial identity verification checks, then our security efforts must extend beyond initial logon.

Intruders impersonate assets in Active Directory

Suppose a malicious actor slips past your identity verification. Perhaps the intruder is a savvy threat actor, or a disgruntled insider who is using legitimate credentials. This may seem like a minor problem, given that their actions are constrained by the permissions they’ve been granted. Few accounts have enterprise admin rights, so how much harm can a general user really do?

One of the first things adversaries do after compromising an account is search for ways to elevate their access. One popular technique is to exploit Group Policy Preferences (GPP). GPP appeared with the release of Server 2008 and allows domain-attached machines to be configured through group policies. Generally, users cannot upgrade their own access. However, PCs can use the credentials of any legitimate logged-in user to authenticate to the domain controller and request policy updates. These policies can make numerous configuration changes to machines, including:

Mapped network drives

Printer configurations

Registry settings

Setting the password for the workstation’s local admin account.

By exploiting GPP, attackers can grant themselves admin access to a compromised machine. From there, they can move laterally through the environment and repeat the process. One compromised workstation quickly becomes 100.

Malicious actors can also exploit vulnerabilities like unconstrained delegation. This allows users or computers to impersonate other accounts to gain access to enterprise resources. Under some circumstances, attackers can use this technique to compromise the host Active Directory (AD) forest and then breach other connected forests.

Consider another example where a verified user’s ability to impersonate another enterprise entity can wreak havoc. A highly damaging object to impersonate in the environment is a domain controller and DCSync attacks allow this by exploiting Microsoft Directory Replication Service Remote Protocol (MS-DRSR). Malicious actors can use this tactic to request and obtain user credentials from legitimate domain controllers. This attack is one of several available through popular hacking tools like mimikatz.

Chaining together numerous tactics provides pathways to laterally move around network locations and permission boundaries. Unless specifically hardened against it, Active Directory Kerberos Service-for-User (S4U) may be abused to get a domain administrator account’s service ticket on a local machine. Service Control Manager may be fooled with fake MachineIDs to bypass User Access Control. The Potato line of attacks specifically use the ImpersonatePrivilege permission to make a service account into NT AUTHORITY/SYSTEM. This method of becoming a local machine admin may be useful for some situations.

As you can see, impersonation techniques play a significant role in cyberattacks once intruders gain a foothold in the environment. This is why identity verification efforts cannot end after validating initial connection requests.

Addressing internal identity-based attack surface

Fortunately, there are solutions that can help you determine where and how your business environment is vulnerable to subtle forms of identity abuse. Identity threat detection and remediation (ITDR) tools can scan your environment for security issues and offer solutions. They offer crucial security coverage, given that 80% of modern attacks are identity-driven.

Specifically, an ITDR can help discover issues like GPP password exposure and other risky configurations in the environment. It provides vital information on the impact and scope of security issues, along with guidance for performing remediation. It also performs real-time monitoring of the environment and alerts analysts as new issues arise. This is an extremely important capability considering the number of account creations, configurations, and modifications happening in the enterprise on a daily basis.

Industry researchers claim Active Directory is involved in 90% of the attacks they witness. By focusing on identity and AD, ITDR tools are securing areas that most attackers ultimately target. Unfortunately, many security practitioners still view identity as a zero-sum game. If you can fool identity verification at log-on, you win access to everything. ITDRs change this dynamic by preventing identity abuse and privilege escalation after the initial identity verification. Too many organizations quit the fight once a user is verified. ITDR lets organizations battle on, which greatly elevates their security posture and makes life harder for threat actors. 

Learn more about mitigating the risk of identity-based attacks here.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : CIO – https://www.cio.com/article/656271/addressing-the-insecurity-of-verified-identities.html

Tags: addressingbusinessinsecurity
Previous Post

The biggest enterprise technology M&A deals of the year

Next Post

Multicloud by design approach simplifies the cloud experience

Chimpanzees use medicinal leaves to perform first aid – Frontiers

Chimpanzees use medicinal leaves to perform first aid – Frontiers

May 23, 2025
Three Students Earn National Science Foundation Graduate Research Fellowships – UConn Today

UConn Students Shine as National Science Foundation Graduate Research Fellowship Recipients!

May 23, 2025
Modern Ag Alliance Urges Science-Based Agricultural Policy in Response to MAHA Commission Report Questioning Crop Protection Tools – Morningstar

Modern Ag Alliance Calls for Science-Driven Agricultural Policies Following MAHA Commission’s Crop Protection Report

May 23, 2025
Summer must-haves from lifestyle contributor Limor Suss – WWLP

Essential Summer Must-Haves You Can’t Live Without!

May 23, 2025
New World drags Hong Kong banks into a loan tango – Reuters

New World Sparks a Loan Tango for Hong Kong Banks

May 23, 2025
Droughts are major threat to Eurozone economy, warns ECB – Financial Times

ECB Sounds Alarm: Droughts Pose Significant Risk to Eurozone Economy

May 23, 2025
Embracer intends to spin off Coffee Stain Group by the end of 2025, with remaining business rebranded as Fellowship Entertainment – GamesIndustry.biz

Embracer intends to spin off Coffee Stain Group by the end of 2025, with remaining business rebranded as Fellowship Entertainment – GamesIndustry.biz

May 23, 2025
Read the Full ‘Make America Healthy Again’ Report – The New York Times

Discover the Insights of the ‘Make America Healthy Again’ Report!

May 23, 2025
‘OPB Politics Now’: An inside look at how OPB covers the Oregon Capitol – Oregon Public Broadcasting – OPB

Behind the Scenes: Discover How OPB Captures the Heart of Oregon Politics

May 23, 2025
Gainbridge® Campaign Wins Sports Business Awards’ Brand Activation of the Year – LPGA

Gainbridge® Campaign Wins Sports Business Awards’ Brand Activation of the Year – LPGA

May 22, 2025

Categories

Archives

May 2025
MTWTFSS
 1234
567891011
12131415161718
19202122232425
262728293031 
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (631)
  • Economy (644)
  • Entertainment (21,557)
  • General (15,226)
  • Health (9,685)
  • Lifestyle (649)
  • News (22,149)
  • People (647)
  • Politics (652)
  • Science (15,868)
  • Sports (21,154)
  • Technology (15,633)
  • World (634)

Recent News

Chimpanzees use medicinal leaves to perform first aid – Frontiers

Chimpanzees use medicinal leaves to perform first aid – Frontiers

May 23, 2025
Three Students Earn National Science Foundation Graduate Research Fellowships – UConn Today

UConn Students Shine as National Science Foundation Graduate Research Fellowship Recipients!

May 23, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version