Navigation
Search
|
SMS text two-factor authentication "bypassed at scale"
Wednesday December 19, 2018. 04:39 PM , from BoingBoing
Gmail's text-message two-factor authentication is not only insufficiently secure, but 'bypassed at scale', reports Joseph Cox.
A new Amnesty International report gives more insight into how some hackers break into Gmail and Yahoo accounts at scale, even those with two-factor authentication (2FA) enabled. They do this by automating the entire process, with a phishing page not only asking a victim for their password, but triggering a 2FA code that is sent to the target’s phone. That code is also phished, and then entered into the legitimate site so the hacker can login and steal the account. I use Authy.
https://boingboing.net/2018/12/19/sms-text-two-factor-authentica.html
|
25 sources
Current Date
Nov, Thu 21 - 21:37 CET
|