9. of Spoofing I
An attacker who gets a password can reuse it (use stronger authenticators).
Threat |
|
An attacker might shoulder surf and read what you are typing or use a key logger attached to your computer to steal your password, which they can then reuse because you don’t require additional factors (token, biometric, FIDO2). |
|
CAPEC |
CAPEC-560 - Use of Known Domain Credentials |
ASVS |
2.2.6 - Verify replay attack protections are in place and working correctly |
CWE |
CWE-308 - Use of Single-factor Authentication |
Mitigations |
|
|