Multi-Factor Authentication Discussion [WRITE-UP]

Let’s discuss Multi-Factor Authentication.

Nice room. Just follow the instructions to complete. Here are answers if you need.

How MFA Works

Question: When logging in to the application, you receive an SMS on your phone containing the OTP. What authentication factor is this?
Answer: Something you have

Implementations and Applications

Question: Is MFA an important factor in keeping our online and offline activities safe from threat actors? (yea/nay)
Answer: yea

Common Vulnerabilities in MFA

Question: What can be implemented to help prevent brute-forcing OTPs?
Answer: rate limiting

Practical - OTP Leakage

Question: What is the flag in the dashboard?
Answer: 904c8ac84e44f0ba942e9e11ee7037b8

Practical - Insecure Coding

Question: What is the flag in the dashboard?
Answer: 87880e9d27001affdff90989f351c46

Practical - Beating the Auto-Logout Feature

Question: What is the flag in the dashboard?
Answer: 20548e076dbb9ba30c9d94ae4aceb38e