Download PDF version Contact company

Transport for London (TfL) announced that it will be introducing multi-factor authentication (MFA) to its Oyster and contactless users this year.

Usernames and passwords, which is the authentication that TfL currently uses for users, have long been the default method of online authentication, but have been proven to be ineffective at mitigating modern cyber-attacks.

Multi-factor authentication (MFA)

By requiring MFA, Transport for London (TfL) is providing extra security for its users, when accessing their personal information on the TfL app or website.

Multi-factor authentication (MFA) is a more secure alternative to passwords, requiring a user to provide two or more forms of unique evidence. This is to verify their identity, permit access to their digital accounts or information, and protect their data from being compromised by cyber-attacks.

Online users need to set up MFA identity verification

It’s encouraging to see that TfL is one step closer in improving online security for its customers"

Following TfL’s update, when creating a new account or signing into an existing account, online users will be required to set up MFA identity verification. Customers will receive a six-digit code on their mobile device that they must enter via a prompt at each sign-in.

Niall McConachie, the Regional Director (UK & Ireland) at Yubico, welcomes this change by TfL and encourages more UK organizations to offer MFA to their online users. He said, “It’s encouraging to see that TfL is one step closer in improving online security for its customers. However, it is also important to note that not all MFA is created equal, and some forms of MFA are more secure than others.

Countering a wide range of modern cyber threats

Niall McConachie adds, “For example, mobile devices certainly offer us ease of access, convenience, and a sense of security – until they are broken, lost, or even stolen. And while SMS, one-time passcodes, and mobile authentication apps are more secure than passwords, these methods are still susceptible to a variety of common cyber-attacks.

He continues, “Account takeovers, phishing, and man-in-the-middle attacks are just some of today’s most prolific attacks that can potentially lead to a ransomware attack or data breach later on, which would be devastating for any organization and its customers.

Implementing modern MFA approaches

Niall McConachie said, “Ultimately, mobile devices have countless uses to those who use them, but they are not designed for cyber security purposes. The perception that usernames, passwords, or mobile devices are effective and secure authentication methods to private data is incorrect and must change – especially when personal, financial and location data is all up for grabs from hackers.

He adds, “With this in mind, TfL and other UK organizations should work towards implementing more modern MFA approaches, including passwordless authentication solutions. These offer strong phishing resistance and are proven to stop account takeovers in their tracks.

Download PDF version Download PDF version

In case you missed it

The Impact of the Cloud on Physical Security: Net-Positive or Net-Negative?
The Impact of the Cloud on Physical Security: Net-Positive or Net-Negative?

Migrating to the Cloud can be a cultural shift for some organizations, especially when it comes to physical security systems. Challenges such as concerns about data security and co...

New Johnson Controls FX90 Supervisory Controller Maximizes Building Automation Performance, Reliability And Flexibility
New Johnson Controls FX90 Supervisory Controller Maximizes Building Automation Performance, Reliability And Flexibility

Johnson Controls, the global pioneer for smart, healthy, and sustainable buildings, launches the Facility Explorer FX90 Supervisory Controller, packed with unique, advanced feature...

HID Announces Integration With Q2’s Digital Banking Platform To Help Change How Banking Customers Authenticate
HID Announces Integration With Q2’s Digital Banking Platform To Help Change How Banking Customers Authenticate

As cyber threats continue to evolve, the need for robust authentication solutions in the banking sector becomes increasingly evident. Traditional methods, such as SMS OTP for banki...