Earlier quoted context omitted.
The only way I see this problem going away is when regular retailers start supporting software and hardware two factor authenticators. I use Google Authenticator on any website that supports it and it does not impact the customer experience at all and it really improves security.
Agreed, but keep account recovery in mind. Account recovery is a major pain point for any site that supports TOTP 2FA. If you're not using a TOTP application that supports cloud backup (like Authy), when you lose or replace your mobile device the existing TOTP tokens are useless as they can't be recovered. This results in some type of account recovery process to reintroduce the 2FA tokens. Often these recovery proces…
Hackers account for 90% of login attempts at online retailers
11–20 of 65 posts
Re: Hackers account for 90% of login attempts at online retailers
#12Re: Hackers account for 90% of login attempts at online retailers
#13I recently joined a website the did away with passwords, the only way to login was to enter your email address and confirm by pressing a link in the email, while this adds a pain point for customers it offloads most security implications onto the email provider.
Re: Hackers account for 90% of login attempts at online retailers
#14I recently joined a website the did away with passwords, the only way to login was to enter your email address and confirm by pressing a link in the email, while this adds a pain point for customers it offloads most security implications onto the email provider.
Re: Hackers account for 90% of login attempts at online retailers
#15I recently joined a website the did away with passwords, the only way to login was to enter your email address and confirm by pressing a link in the email, while this adds a pain point for customers it offloads most security implications onto the email provider.
Passwords can already universally be recovered through email. I wish ALL sites had this feature. It's essentially a one time password, that expires.
Re: Hackers account for 90% of login attempts at online retailers
#16I recently joined a website the did away with passwords, the only way to login was to enter your email address and confirm by pressing a link in the email, while this adds a pain point for customers it offloads most security implications onto the email provider.
It's really no less secure than allowing someone to sign up with an email / password and let them in without first confirming their email address.
Re: Hackers account for 90% of login attempts at online retailers
#17Re: Hackers account for 90% of login attempts at online retailers
#18Article doesn't talk about what they're doing to mitigate the problem. Well, except tell the reader to change their passwords. So are online retailers just hoping the problem goes away?
They have to balance user attention and user friction. Online retailers want your purchase to be as smooth as possible. There's some studies on how someone won't spend much time on a website if it loads slow. The same can apply to purchase decisions. They need it as impulsive as possible. So annoying things like 2 factor authentication, in their mind, might make a customer give up their purchase. So things are insecu…
Re: Hackers account for 90% of login attempts at online retailers
#19"[...] we rely on data from the Shape Network. Across the US, Shape’s customers represent: [..] 40% of Mobile Retail (by in-store payments)."
"We estimated the number of credential stuffing attacks using the total number of credential stuffing attacks observed on Shape’s US customers and the total proportion of the US industry our customers represent."
I'm really wracking my brain how they're measuring their marketshare of retail. Mobile retail as measured by in-store payments? Can someone explain that to me?
Bottom line, this data comes from a company whose value proposition is that they sit between your company's servers and your clients and filters bad requests for you.
Re: Hackers account for 90% of login attempts at online retailers
#20I recently joined a website the did away with passwords, the only way to login was to enter your email address and confirm by pressing a link in the email, while this adds a pain point for customers it offloads most security implications onto the email provider.
I also do this with websites I make. It is a little inconvenient, but it's worth it, assuming the person logging in as a secure way to access their email (2 factor auth).