Deep Dive: Forter Account Protection with Auth0 Actions Reduces Friction and ATOs – Forter
Account Takeover (ATO)
Account Takeover (ATO) attempts are increasing 55% year over year, and they are relatively easy for attackers to execute. An attacker can obtain a username+password combination in several ways: via a marketplace on the dark web, or by tricking (phishing) a user, or by simply guessing a poorly-constructed password.
Impact of ATO
Once an attacker has obtained a user’s password, they can log in to the user’s account and potentially perform all kinds of bad actions: make purchases with the user’s stored credit card, redeem the user’s loyalty points, or even change the user’s original password so that the attacker has exclusive access to the account.
Multi-factor Authentication (MFA)
One of the most effective ways to foil an ATO attempt is to require Multi-factor authentication (MFA), so that a bad actor needs not only a password but also an SMS code or some other factor to successfully log in to an account.
While MFA is certainly effective at reducing successful ATO attempts, it adds friction to the experience of valid users as well, often causing them to abandon a site or a purchase. We’ve all been there – having to pull out your phone can cause you to just close the site altogether.
Challenges with MFA
Given the negative effect of MFA on valid users, identity providers have tried to become more sophisticated and targeted in issuing MFA challenges. However, these attempts usually result in complicated rules (block certain IP addresses, new machines, etc.) that are difficult to maintain and troubleshoot, and often ineffective in blocking sophisticated ATO attempts which intentionally circumvent the rules.
Addressing the Challenge
Forter’s Account Protection solution addresses this challenge by looking at the user context and comparing it against a proprietary dataset of identities established through their fraud prevention solution.
When a user logs in to a website, and after completing password authentication, a request goes to the Forter APIs. If it comes back positive, the user is simply let into the website. Otherwise, and only for suspicious cases, the user is prompted to perform MFA.
To achieve such accuracy, Forter looks at not only the "hard" data points related to a user — IP address, OS, etc. — but also how that user has historically behaved on the web. Forter has helped many customers achieve great improvement in reducing friction while increasing security at login.
Integration Challenges
However, if you’re using an identity provider, it can be a challenge to integrate an external solution such as Forter into your authentication flow. Identity providers’ login rules often do not support incorporating an external decision engine, making it difficult to separate the evaluation of the username and password from the MFA policy.
Enter Auth0 and Actions Capability
Auth0 offers an Actions capability that allows you to call out to an external decision engine during the authentication flow. This capability allows you to pause the authentication flow and automatically call out to Forter to get an accurate recommendation regarding how to handle the authentication attempt: allow, deny, or challenge. The Action allows you to either let the user continue with their authentication, deny the attempt altogether, or invoke the Auth0 MFA engine to challenge the user for a second factor.
This evaluation happens in milliseconds after the user’s username and password have been verified by Auth0 but before Auth0 issues an ID token to represent the authentication.
Auth0 can also host your login page for you, and the Forter javascript library works seamlessly with the Auth0 lock.js front-end library, allowing the user context to flow to the back end Action.
Conclusion
In summary, using Forter and Auth0 together provides:
- Your application does none of the “heavy lifting” during the authentication process
- Your application gets authenticated users vetted by Forter’s ATO prevention solution
- Your valid users experience far less friction during authentication
- Bad actors are blocked by MFA or outright denied
It’s a powerful combination of Auth0’s authentication capabilities and Forter’s accurate decision engine.