WinMagic Targets Adversary-in-the-Middle Attacks with Cryptographic Shift
Artificial intelligence has weaponized cyberattacks, making phishing lures cheaper and more effective. Thi Nguyen-Huu, CEO of WinMagic, warns that current multifactor authentication often fails against adversary-in-the-middle attacks because the systems cannot distinguish between a legitimate user and a relaying attacker sitting in the middle of a session.

The core vulnerability lies in the separation between the login process and the subsequent active session. Most systems verify a user's identity once, then hand off access, creating a gap that attackers exploit to intercept communications. Nguyen-Huu argues that this model is outdated, as it relies on human-managed credentials rather than machine-to-machine cryptographic certainty.
To bridge this gap, WinMagic proposes a framework called Live Identity in Transaction (LIT). Instead of relying on passwords or one-time codes, this approach requires the endpoint device to generate a cryptographic key tied directly to the specific service being accessed. By automating this process, the device verifies the user and the session continuously without requiring manual input. The company has already submitted proposals to the World Wide Web Consortium and the Internet Engineering Task Force to standardize this interaction.
While the technology aims to automate security, Nguyen-Huu remains cautious about labeling any solution as unphishable. The goal is to remove the human element from the verification process, effectively turning user-to-machine communication into a machine-to-machine relationship. By binding authentication to the transaction itself, organizations can theoretically eliminate the window of opportunity that attackers currently use to relay credentials in real time.
Comments (0)
No comments yet. Be the first!