Enterprises are putting too much faith in Single Sign-On, which is making breaches worse (2024)

Enterprises are putting too much faith in Single Sign-On, which is making breaches worse (1)

Single sign-on (SSO) provides a quick and easy means of access across many applications by using a single set of login credentials, and helps employees save time by removing the need to log in to each individual account and removing the need for a password manager.

However, security researchers at Doyensec, in collaboration with Teleport, have found enterprises are becoming over reliant on SSO, and are failing to put in place additional layers of security between SSO and the applications they access.

For attackers, SSO can be a gold mine for infiltrating an organization, making companies reliant on the technology an attractive target for attackers.

Convenience is putting businesses at risk

In testing performed by the researchers against Azure Active Directory, Entra ID, Google Workspace, Github and Okta, they found that attackers use a wide range of techniques to gain access to an Identity Provider (IdP), including password spraying, access token leakage, prompt-bombing, spear phishing, social engineering, employee bribing, credential stuffing and session hijacking.

“No SSO provider should be assumed to be secure,” Ev Kontsevoy, CEO at Teleport said. “With SSO, if one individual’s identity is compromised, you could be handing over the master key to the castle. SSO does offer considerable convenience, but unauthorized access to one individual’s credentials exposes every platform and service for which that individual has privileges. Without additional defense in place, SSO by itself does not thwart identity-based attacks.”

A successful attack against an IdP provider, especially if it goes undetected, can result in user impersonation, theft of sensitive company and user data, and the creation of new credentials for malicious use.

In order to mitigate the threats presented by compromised IdPs, the researchers recommend operating on a defense-in-depth model by layering phishing-resistant MFA-based features, access requests and dual authorization to enforce principles of least privilege, and putting mandatory MFA enrollment in place to make it more difficult for attackers to breach systems and move laterally.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

“What’s clear is that vulnerabilities in SSO and IdP platforms can have catastrophic impacts,” Luca Carettoni, CEO at Doyensec said. “Applying a defense-in-depth security layer on top of service providers can significantly limit the outcomes of a successful SSO provider compromise and reduce the impact against the protected infrastructure. The configuration of the defense-in-depth layer is extremely important to a company’s overall defense posture.”

More from TechRadar Pro

  • These are the best endpoint protection services
  • Security bug could have allowed anyone to spoof Microsoft employee emails
  • Take a look at the best antivirus
Enterprises are putting too much faith in Single Sign-On, which is making breaches worse (3)

Benedict Collins

Staff Writer (Security)

Benedict has been writing about security issues for close to 5 years, at first covering geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division). Benedict then continued his studies at a postgraduate level and achieved a distinction in MA Security, Intelligence and Diplomacy. Benedict transitioned his security interests towards cybersecurity upon joining TechRadar Pro as a Staff Writer, focussing on state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

More about pro

How the laptop could become the battery — new revolutionary carbon-based material means your laptop chassis could become a power source, eliminating the need for a traditional battery"World's Fastest Storage Device" — Highpoint card paired with eight of the quickest SSDs delivers a staggering 60GBps in read performance but it will cost you dear

Latest

Quordle today – hints and answers for Sunday, June 23 (game #881)
See more latest►

Most Popular
Samsung may have confirmed the Galaxy Watch Ultra name on its own website
ICYMI: the week's 7 biggest from potential DJI drone bans to new film cameras
Would you eat a robot? Swiss scientists want to create fully edible electronics — but I am not sure I want to have a bite at R2D2 anytime soon
Report: Amazon might ask you to pay for the best Alexa
Spotify launches new Basic Plan in the United States – here's what you need to know
Quordle today – hints and answers for Saturday, June 22 (game #880)
NYT Connections today — hints and answers for Saturday, June 22 (game #377)
NYT Strands today — hints, answers and spangram for Saturday, June 22 (game #111)
Have an Apple Watch? You can get a rare, limited edition badge today – but you'll need to act fast
Apple won't bring Apple Intelligence to EU 'over regulatory uncertainties' and data concerns
Exclusive: first 128TB SSDs will launch in the coming months — and yes, this little-known rival will challenge Samsung, Solidigm, Kioxia for the storage capacity crown
Enterprises are putting too much faith in Single Sign-On, which is making breaches worse (2024)
Top Articles
Latest Posts
Article information

Author: Eusebia Nader

Last Updated:

Views: 6361

Rating: 5 / 5 (60 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Eusebia Nader

Birthday: 1994-11-11

Address: Apt. 721 977 Ebert Meadows, Jereville, GA 73618-6603

Phone: +2316203969400

Job: International Farming Consultant

Hobby: Reading, Photography, Shooting, Singing, Magic, Kayaking, Mushroom hunting

Introduction: My name is Eusebia Nader, I am a encouraging, brainy, lively, nice, famous, healthy, clever person who loves writing and wants to share my knowledge and understanding with you.