Rogue external MFA providers can steal passwords during logins
Posted by PrivacyWire
This matters because a rogue external MFA provider could capture passwords during legitimate logins, even when users believe multi-factor authentication protects them. It also shows that privileged control over authentication systems can undermine privacy and security by turning trusted login infrastructure into a way to collect credentials. Has your organization reviewed which external MFA providers have privileged access to its login systems?