Security

Not Every MFA Is Created Equal

Traditional multi-factor authentication no longer stops reverse-proxy phishing. Here are the tools Macktez uses to protect your online accounts from session hijacking.

February 3, 2025

Macktez has long pushed clients to turn on multi-factor authentication (MFA) everywhere it's available. But attackers have found ways around the MFA most people rely on, so protecting your accounts now takes some new tools alongside the old ones.

How can you best secure your online accounts?

For many years, we have asked clients to enforce MFA on every platform where it's offered. By requiring a time-based one-use code in addition to the usual username and password, users protect their accounts from unauthorized access even if a password is compromised.

But attackers keep innovating, and there are now several ways for criminals to trick users into giving away both their password and their MFA code. The attack starts with an email from a legitimate contact (not faked) and leads to a web page showing a legitimate login screen for a service you use, like Google or Microsoft (again, not faked). By logging in, you hand an attacker access for as long as that service keeps a single browser session alive, often 14 days or longer.

These attacks are technically called "reverse-proxy phishing" and lead to "session token hijacking." This blog post explains how it works and why it's so insidious: How legacy MFA is no longer keeping you safe.

To protect yourself, you need some new tools added to your old ones.

First, the old tools: your eyes and your brain

Even though the email with a link is from someone you know and the address is not faked in any way, were you expecting that email? Is it normal for this person to reach out with an opportunity that requires you to click a link? Does the link have a URL you recognize? Are you surprised when it asks you to sign into your Google, Microsoft, or Dropbox account?

Never follow along blindly. Always pay attention to where you are being led and what action you are being asked to take. If your Spidey sense tingles at all, take a step back and reconsider.

In particular, if you are ever asked to enter credentials, triple-check the URL in your browser. Are you logging into Microsoft at login.live.com or login.llve.com? One is a legitimate Microsoft page; the other is not a typo, it's a hacker's hideout.

New tools to verify your identity

If attackers are innovating, cybersecurity experts need to innovate too. They have, and there are already established tools that protect users from reverse-proxy phishing:

  • Federating user verification to a third-party identity provider breaks the flow of data in a reverse-proxy attack, hiding critical authentication steps from attackers. Federated identity is a central feature of Macktez Identity Management.
  • Requiring a phishing-resistant authentication method as part of MFA further keeps attackers from getting the credentials they need. That means setting aside the MFA tools most people rely on, like SMS codes, time-based codes generated by apps, and push notifications. Instead, adopt a tool using the WebAuthn protocol that responds only to requests from legitimate websites and bypasses the back-and-forth data transfer attackers can intercept, such as fingerprint readers, facial recognition, and physical security keys.
  • Adding conditional access policies such as geographic location or IP address verification locks out attackers from an unauthorized location, even if they do manage to pinch your credentials.

Macktez Identity Management includes all of the above

  1. Macktez Identity Management relies on JumpCloud as the third-party identity provider. Microsoft, Google, and other online services federated to JumpCloud are redirected there for authentication, which is Step One in thwarting an attempt to hijack a session token.
  2. Step Two is enforcing a feature called JumpCloud Go, which leverages biometric identification on your computer to authorize access to federated online services.
  3. Step Three, for clients who need additional protection, is to configure any number of conditional access policies at JumpCloud to dramatically reduce the number of ports for entry.

These are the best cybersecurity tools available to your organization right now. Macktez is well-prepared to implement these policies to protect your users from criminals, and to stay prepared for whatever new threats materialize.

Work With Us

Have a project like this on the horizon?

If something here maps to what your organization is facing, let's talk it through — no pitch deck, just a senior technical perspective on your situation.