ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Security by obscurity keeps us password-dependent

We need security by community. Andrew Shikiar of the FIDO Alliance calls on more businesses to see that sharing is caring when it comes to cyber security 

 

60 seconds. 76 employees. One innocent-looking identity platform page. 

 

Back in June, two cloud computing giants revealed they were targeted by a near-exact phishing attack. Cloudflare reported 76 of its employees received text messages within one minute from a supposed IT department, which directed employees to a fake website requesting a password change.

 

In fact, dozens of companies were victims of the same attack (dubbed 0ktapus as it targeted cloud service providers that use Okta for employee authentication).  

 

Neither Twilio nor Cloudflare’s monitoring systems detected the attack, given its accuracy in mimicking the ID platform. And, as you’d expect, several employees were caught off guard and shared their credentials.

 

However, unlike Twilio, Cloudflare’s story ended far more happily, as FIDO security keys that are tied to users and implement origin binding prevented any credentials from being shared. 

 

Their outcomes were very different, but the sentiment of these two companies were the same – we’ve been targeted, this is how, this is what we can learn. Here’s why more businesses need to do the same, and what any organisation can do to best arm themselves against cyber attacks. 

 

Security by obscurity – OK, Boomer!

There’s an old IT industry adage that security by obscurity is the best way to protect your organisation. The theory is that by not revealing how you are securing your systems, or how and when you are attacked, you are more protected from an attacker who might use this information against you.

 

This is an outdated approach to security. It’s not fit for modern cyber attacks or today’s digital world. In fact, by keeping the true state of security under wraps, we’re only creating a broader surface area of attack for hackers. 

 

Attacks on enterprises and SMEs are rising year on year, while the ever-increasing cost of cyber insurance premiums is making it a luxury inaccessible to many organisations.

 

Passwords are, undeniably, the single biggest cause of breaches and risk. As we move into a gloomier economic climate, we cannot continue a siloed approach of stabbing in the dark when it comes to fighting off cyberattacks and bringing in a passwordless age.

 

Cyber security should be a top priority for organisations of all sizes, and a community approach that champions transparency and collaboration is going to be key to survival. 

 

Transparency and collaboration 

The benefits of moving to MFA are widely reported on. While not all MFA is created equal (witness Twilio’s cautionary tale above), any form of MFA is better than a password alone to protect an account. But many organisations have been sheepish in sharing the status of their adoption figures. 

 

Twitter set a great example last summer in revealing its 2FA adoption rates. While the stats aren’t great – just 2.3% of accounts enabled 2FA and of those 80% relied on SMS-based backup, the least secure mode – the sharing itself is worth celebrating. The willingness to be open is outstanding and gives a powerful benchmark for improvement, as well as giving the industry a reality check that considerable work needs to be done to get consumers on board and more accounts protected. 

 

Transparency goes hand in hand with collaboration. Solving a problem as big as passwords and online security needs the combined efforts of multiple industries and organisations. Twilio, Twitter and Cloudflare are all contributing to shared knowledge to inform the shape of the challenge, how we solve it, and what still needs to be done.  

 

Best practice – how can businesses best arm themselves? 

The FIDO Alliance is composed of some of the world’s biggest tech companies and consumer service providers - spanning industries and borders. Together, we’ve created technology that’s increasingly cited as a ‘gold standard’ by governments. Most recently, FIDO was called out by the UK’s National Cyber Security Centre (NCSC) in guidance to organisations with an online presence like retailers, hospitality providers and utility services, to protect themselves and their customers. 

 

FIDO Authentication features mature and readily available security protocols and is a highly effective foundation for an organisation to secure itself today - as the Twilio/Cloudflare example shows.

 

It is often implemented with USB keys or with built-in biometric authentication on devices, and can be added as a critical layer of security to both an organisation’s own network and information, and for customers accessing its services. 

 

Soon, we’ll also start seeing added momentum for FIDO authentication of consumer services through the advent of passkeys - which Apple, Microsoft, and Google have all committed to support in their devices and operating systems.

 

Passkeys serve as FIDO-based password replacements that will be seamlessly available across a user’s devices and stand to be transformative in how consumers sign into online services as the user experience will be very tightly integrated into the device and browser user flows. 

 

In it together – the mindset shift we need to bring down passwords

While creating and implementing new technology is an important part of moving the world away from passwords, it isn’t the most critical piece. Industry-wide commitment to creating intuitive and common user journeys underpinned by architectural best practices will enable the cultural shift and mass adoption of this technology that is required to succeed in removing passwords from our daily lives.  

 

Virtually every organisation across the world has a stake in making the internet a safer, more user-friendly space.  Collaboration and transparency are required ingredients that raise the bar for all involved - including for hackers, who will have a harder time executing remote attacks. 

 


 

Andrew Shikiar is an Executive Director at the FIDO Alliance

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543