# The Layer Below Your Password Is Now the Target


For years, the security industry's answer to compromised credentials was a second factor. Get phished? The attacker still needs your phone. It was a reasonable assumption — right up until attackers stopped needing your phone.


The mechanics have shifted. Adversary-in-the-middle phishing kits like Evilginx and Modlishka have been around for years, but they required technical sophistication and real-time operator attention. AI changes the economics of that equation dramatically. Automated spear-phishing campaigns that once took hours of OSINT and manual crafting can now run at scale, personalized, against thousands of targets simultaneously. The lure that gets someone to click on a credential-harvesting proxy isn't a generic "your password has expired" email anymore — it's a message that knows your manager's name, your current project, and your internal ticketing system's URL format.


This is the specific pressure that's forcing a rethink of what "trust" means at the authentication boundary.


## What AI Actually Broke


The traditional stack of trust signals — password, TOTP or push MFA, IP geolocation, device fingerprint — was calibrated for a world where attacker velocity was slow. A human operator trying to pivot from a stolen session token had to act quickly and move through detection layers that could catch behavioral anomalies.


AI-assisted attacks remove the human from that loop. Session hijacking after an AiTM intercept can happen in milliseconds. Geolocation anomalies that once triggered risk scoring are now trivially bypassed through residential proxy networks that route traffic through legitimate home IP addresses in the target's city. Push MFA gets defeated through fatigue attacks — bombarding users with approval requests until someone taps "allow" by accident or frustration — or through real-time relay where the attacker mirrors the authentication session faster than any human could catch.


Voice-based MFA is in particularly rough shape. Deepfake audio quality has crossed a threshold where call center authentication flows are genuinely at risk. The $25 million Hong Kong finance company fraud in early 2024 — where a CFO impersonation via deepfake video call moved real money — illustrated that voice and video are no longer reliable identity signals in high-stakes contexts.


IP reputation, geolocation, and behavioral biometrics haven't disappeared as useful signals. But they've been demoted from authentication factors to corroborating indicators, which is a meaningful distinction in how you architect a Zero Trust policy.


## The Case for Device Attestation


If session tokens can be stolen, credentials can be phished, and MFA can be relayed in real time, what's left? The device.


Specifically: a cryptographic attestation that the request is coming from a known, managed, and healthy endpoint. Device trust in modern Zero Trust implementations typically means a few things in combination:


  • Certificate-based authentication tied to a hardware TPM or Secure Enclave that can't be exported
  • Device compliance checks that verify patch level, EDR enrollment, disk encryption status, and configuration posture at access time — not just at enrollment
  • Continuous verification rather than one-time-per-session authentication

  • The key property here is that a stolen session cookie or credential doesn't help an attacker if the downstream resource checks whether the request is cryptographically bound to a specific piece of hardware. Phishing the password is useless if the relying party requires a TPM-signed proof-of-possession that never leaves the device.


    This is why major identity providers and SaaS platforms have been quietly moving toward passkeys and device-bound credentials over the last two years. FIDO2 WebAuthn — when implemented correctly, with no fallback to SMS or push — is resistant to AiTM attacks because the credential assertion is bound to the origin domain and signed by hardware the attacker doesn't possess.


    ## Where It Gets Complicated


    Device trust is not a clean solution. It introduces a different class of problems.


    The most significant is the BYOD gap. Enterprises that allow personal devices to access corporate resources have always struggled with this, but the stakes are higher now. Personal devices that aren't enrolled in MDM don't have verifiable posture. If your Zero Trust policy requires device health checks but your access model still allows unmanaged personal phones as a fallback, you've built a wall with a door in it.


    There's also the supply chain question that rarely makes it into vendor briefings: what happens when your device attestation infrastructure is compromised? The 2020 SolarWinds incident demonstrated how thoroughly a trusted software update mechanism could be weaponized. A compromise of an MDM platform or certificate authority used for device attestation could, in theory, allow attackers to mint "trusted device" certificates for attacker-controlled machines. The trust model only works if the root of that trust is genuinely secured.


    Finally, there's the forgotten population: third-party contractors, partners, and acquired companies accessing resources through federation. Device trust policies that work cleanly for direct employees often have jagged edges at the federation boundary. An attacker who can't breach your corporate devices may find a softer path through a partner organization with weaker device hygiene.


    ## What Defenders Should Actually Do


    The honest answer is that no single layer is sufficient. Device trust raises the floor — it makes credential phishing materially less useful as an entry vector. But it isn't a replacement for the full Zero Trust framework; it's an addition to it.


    Practical priorities:


  • Audit your MFA methods and eliminate SMS and voice OTP as factors. If you're still relying on these, you're behind.
  • Enforce device compliance checks at resource access time, not just at login. A device that was clean in January may be running unpatched software today.
  • Map your BYOD and contractor access surface. Every exception to your managed device policy is a potential gap.
  • Test your AiTM resistance. Red teams that specifically simulate Evilginx-style proxy attacks against your authentication flow will surface weaknesses faster than theoretical reviews.
  • Plan for credential hierarchy compromise. What does your incident response look like if your MDM vendor is breached? That's not a hypothetical question anymore.

  • ---


    ## HackWire Analysis


    The framing of "device trust vs. credentials" understates what's actually happening here: we're watching the authentication industry quietly acknowledge that password-plus-MFA was always a temporary fix, not a durable solution.


    The Okta breach cascade of 2023 was instructive in ways that still aren't fully processed. Okta — a company whose entire value proposition is identity security — had its support system compromised, leading to downstream customer breaches. The attack surface wasn't clever zero-days; it was support credentials, session tokens, and the implicit trust that internal tooling receives. Device trust wouldn't have fully closed that gap, but it would have raised the cost of lateral movement significantly.


    What this current AI-driven moment really does is accelerate a reckoning that was already coming. The identity perimeter was always going to need hardware roots of trust — it was just easier to defer when attacks were slower and phishing was more obvious. AI-personalized phishing at scale, voice deepfakes that defeat call center verification, and automated session token relay have collectively made that deferral untenable.


    The specific risk that isn't getting enough coverage: small and mid-size businesses that rely on consumer-grade cloud accounts for critical operations. Microsoft 365 and Google Workspace have passkey support, but most SMBs haven't moved their authentication beyond basic push MFA. These organizations are now facing the same threat sophistication as enterprises, without enterprise security teams. That gap is where the next wave of financially motivated attacks will concentrate.


    Device trust matters. But the real work is making it accessible outside Fortune 500 security teams.


    — HackWire Editorial


    ---


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)