Join our Newsletter — 33% off our NHI Course

x.509 certificates and FIDO: are your authentication controls enough?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Identity-based attacks using stolen credentials have risen by 71% and now drive some of the most damaging cloud breaches, according to IBM and the Snowflake-linked incidents discussed by Axiad. The lesson is structural: MFA alone is not enough when phishing, credential reuse, and third-party access remain viable entry points.

Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Identity Gaps: The Need to Use Both x.509 & FIDO”.

By the numbers:

  • IBM reported a 71% rise in attacks using valid login credentials.

Key questions

Q: What breaks when MFA is configured with weak, phishable factors?

A: Weak factors such as SMS codes, OTP apps, or push-based approvals can satisfy a policy checkbox while still leaving the environment open to phishing, man-in-the-middle, and push bombing attacks.

Q: Why do valid credentials still drive major cloud breaches?

A: Valid credentials work because they look legitimate to the access layer.

Q: What do security teams get wrong about passwordless authentication?

A: The most common mistake is treating passwordless as a user-experience upgrade instead of an identity control change.

Practitioner guidance

  • Map authentication coverage by access path Inventory every user, third-party, and service access path and record whether it is protected by phishing-resistant authentication or still depends on a phishable fallback.
  • Prioritise non-MFA cloud accounts for remediation Find cloud and demo accounts that can still authenticate without phishing-resistant controls and move them into the highest-risk remediation queue.
  • Deploy x.509 certificates where managed trust exists Use certificate-backed authentication for managed endpoints and sensitive enterprise applications where device control and operational consistency make the model sustainable.

Bottom line: Identity-based attacks keep succeeding because the real control failure is incomplete coverage, not the absence of MFA as a policy.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Identity attack surface is now an authentication design problem, not a policy problem: The article shows that the real gap is not the presence of MFA, but the unevenness of its deployment and the number of alternate entry paths still available. If a cloud environment allows phishable authentication, third-party accounts, or legacy access to remain in circulation, the attack surface is already too broad. Practitioners should treat authentication architecture as part of identity attack surface management, not as a standalone login control.

A question worth separating out:

Q: How should organisations combine x.509 certificates and FIDO?

A: Use them as complementary controls, not competing ones. Certificates fit managed enterprise access where device trust and workflow stability matter, while FIDO is ideal for eliminating passwords where platform support is available. The right model is coverage-based, with each method filling the other’s gaps.

👉 Read our full editorial: Identity attack surface gaps show why x.509 and FIDO both matter


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.