Why identity needs a heartbeat, not a checkpoint

https://cdn.mos.cms.futurecdn.net/vAk5oh4pWzGeSY7xpMFAwR-2560-80.jpg

Think about what you had to do the last time you needed to prove your identity.

Did you present your ID? Snap a selfie? Pass a liveness check? In most cases of enterprise security, that’s all it takes to pass through. From that point, many systems effectively assume that the person who was verified remains the person controlling the session.

But that’s increasingly not the case.

Identity checks haven’t suddenly stopped working. Rather, fraudsters and criminals have learned to move around them.

VP of Corporate Affairs at AU10TIX.

The fraud moved past the checkpoint

The modern fraud playbook does not necessarily need to defeat the biometric check at the front door. Session-hijacking malware can take over after a legitimate login. Remote-access tools can turn a verified customer’s device into an attacker’s terminal. Fraud operations can even recruit real people to complete onboarding legitimately before handing the authenticated session...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE