Heartbleed to accelerate adoption of two-factor authentication solutions

Heartbleed
Two factors to every story

A security expert has said that the recent Heartbleed Bug fiasco will encourage more service providers to introduce two-factor authentication.

Speaking to TechRadar Pro at Infosec 2014, JD Sherry, VP of Technology and Solutions at Trend Micro, said that the Heartbleed aftermath will have similar consequences to when LinkedIn, DropBox and others introduced the stronger authentication method after being hacked in 2012.

He said: "A lot of Twitter accounts had been compromised because they weren't using two-factor authentication. Twitter quickly deployed it within eight weeks, and now more companies are going to do the same."

Sherry said that two-factor authentication would have protected people's account information stored on servers vulnerable to Heartbleed.

He added: "Even if your username and password is compromised from a server that's vulnerable to Heartbleed, if that server has two-factor authentication installed, the hacker would need your authenticator or token to be able to truly authenticate with that service."

Barrier to adoption?

However, according to Sherry, service providers (particularly emerging ones) may not be too keen on introducing two-factor authentication as it could prove a barrier to acquiring new users.

He said: "The problem is that people want service adoption on their platform and want to create a frictionless environment for people to get in and use their service.

"Two-factor authentication historically has been friction for getting a service onboard and getting users to adopt the platform, which is why they've been slow to adopt it. The more awareness around Twitter hacks, Heartbleed and on social media that there is, the more two-factor authentication is going to move from what has been best practice out of enterprises to the critical masses."

Kane Fulton
Kane has been fascinated by the endless possibilities of computers since first getting his hands on an Amiga 500+ back in 1991. These days he mostly lives in realm of VR, where he's working his way into the world Paddleball rankings in Rec Room.
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI live stream - could we see a major ChatGPT upgrade?
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection