pwshub.com

Snowflake enables MFA across all new user accounts

Snowflake continues to push forward in strengthening its users' cybersecurity posture by making multi-factor authentication the default for all new accounts.

The imposition follows a lighter-touch move in July when it enabled admins to mandate MFA across their organization's user accounts.

Incident response and threat intel specialist Mandiant investigated a spate of data thefts at Snowflake customers such as Ticketmaster and Santander Bank in May. Its experts found a commonality between all the customers that had experienced such incidents: MFA wasn't enabled.

The individual(s) behind the online alias ShinyHunters claimed responsibility for the breaches. They allegedly stole 1.3TB of data from Ticketmaster concerning circa 560 million people, while in Santander's case, the claim involved details of 30 million accounts and 28 million credit card details. The bank also told Maine's Attorney General that more than 12,000 US employees were affected.

Following these incidents, Snowflake was pressured to make changes, especially during a time when it was still trying to shake the allegations made by security shop Hudson Rock that the breaches were caused by attackers breaking through the data analytics provider's own security. 

These changes came in the form of the mandatory MFA option for admins in July. The latest announcement extends this initiative and then some.

  • Snowflake's Unistore still on ice years after announcement
  • Snowflake claims Iceberg wins table format wars, and Databricks has just proved it
  • Warren Buffett ditches his near-$1B Snowflake investment
  • Three words to send a chill down your spine: Snowflake. Intrusion. Alert

"As part of our continuing efforts, we are announcing that MFA will be enforced by default for all human users in any Snowflake account created in October 2024," said Snowflake CISO Brad Jones and principal product manager Anoosh Saboori. "Service users – accounts designed for service-to-service communication – will not be subject to this MFA requirement."

Passwords also got a boost as the minimum length has increased from 8 to 14 characters and the previous five passwords cannot be reused. This will apply to all newly created and changed passwords, also starting in October. 

This all feeds into Snowflake's long-term ambition to eliminate password-only authentication from its platform, it said, without providing a date for that change.

In the meantime, users were advised to consult the cloud storage and data analytics company's white paper on security best practices to strengthen accounts further.

Snowflake also recommended using single sign-on (SSO) when possible and enabling MFA through the identity provider. If neither is possible or for "break-glass" scenarios, use Snowflake's built-in MFA.

For service accounts, external OAuth should be used where possible, and failing that, enable key pair authentication with network policies. ®

Source: theregister.com

Related stories
1 month ago - Plus: More stalkerware exposure; a $16M TracFone fine; Ransomware victims don't use MFA, and more Infosec in brief Protecting computers' BIOS and the boot process is essential for modern security – but knowing it's important isn't the...
3 weeks ago - The startup hopes to distinguish itself from heavyweights like Google and OpenAI by zeroing in on a niche.
4 days ago - Rain and weather affecting stealth, swords slashing through objects, swathes of generated trees -- and few poorly-rendered pop-ups.
3 days ago - Cloud unicorn struggles to make database that can do everything 'margin positive' Two years after announcing a database that can do analytics and transactions in the same system, Snowflake has yet to commercially launch Unistore, its CFO...
3 weeks ago - The data analytics vendor's CEO says rival's over $1 billion Tabular acquisition is the 'vindication' Databricks' $1 billion plus purchase of Tabular demonstrates Iceberg has won the data table format wars, according to rival data...
Other stories
20 minutes ago - Experts at the Netherlands Institute for Radio Astronomy (ASTRON) claim that second-generation, or "V2," Mini Starlink satellites emit interference that is a staggering 32 times stronger than that from previous models. Director Jessica...
20 minutes ago - The PKfail incident shocked the computer industry, exposing a deeply hidden flaw within the core of modern firmware infrastructure. The researchers who uncovered the issue have returned with new data, offering a more realistic assessment...
20 minutes ago - Nighttime anxiety can really mess up your ability to sleep at night. Here's what you can do about it right now.
20 minutes ago - With spectacular visuals and incredible combat, I cannot wait for Veilguard to launch on Oct. 31.
20 minutes ago - Finding the perfect pair of glasses is difficult, but here's how to do so while considering your face shape, skin tone, lifestyle and personality.