How Hackers Bypass Gmail 2FA at Scale


Recommended Posts

  Quote

 

If you’re an at risk user, that extra two-factor security code sent to your phone may not be enough to protect your email account.

Hackers can bypass these protections, as we’ve seen with leaked NSA documents on how Russian hackers targeted US voting infrastructure companies. But a new Amnesty International report gives more insight into how some hackers break into Gmail and Yahoo accounts at scale, even those with two-factor authentication (2FA) enabled.

They do this by automating the entire process, with a phishing page not only asking a victim for their password, but triggering a 2FA code that is sent to the target’s phone. That code is also phished, and then entered into the legitimate site so the hacker can login and steal the account.

The news acts as a reminder that although 2FA is generally a good idea, hackers can still phish certain forms of 2FA, such as those that send a code or token over text message, with some users likely needing to switch to a more robust method.

“Virtually in that way they can bypass any token-based 2FA if no additional mitigations are implemented” Claudio Guarnieri, a technologist at Amnesty, told Motherboard in an online chat.

2FA is adding another layer of authentication onto your account. With token-based 2FA, you may have an app that generates a code for you to enter when logging in from an unknown device, or, perhaps most commonly, the service will send a text message containing a short code that you then type into your browser.

 

Expand  

 

https://motherboard.vice.com/en_us/article/bje3kw/how-hackers-bypass-gmail-two-factor-authentication-2fa-yahoo

 

In my opinion, this is another benefit of a password manager like lastpass which autofills passwords. If you log in using a password manager it will bot autofill (at least not automatically) your password into a fake website. It goes by the domain. So it will auto fill https://mail.google.com but not https://mail.gooogle.com . So when it doesn't auto fill my passwords, or show a matching passcard(s) to the website, I take one last look at the address bar.

  On 19/12/2018 at 16:45, cork1958 said:

Personally, wouldn't/don't trust a password manager anymore than I trust Trump to tell the truth!! :)

Expand  

I just don't think I can get creative enough to come up with unique passwords for each of the 406 websites. That being said after the last lastpass outage I do keep a currentish import in keepass on 2 disconnect flash drives.

  On 19/12/2018 at 16:48, warwagon said:

I just don't think I can get creative enough to come up with unique passwords for each of the 406 websites. That being said after the last lastpass outage I do keep a currentish import in keepass on 2 disconnect flash drives.

Expand  

Holy crap! 406 websites that you have an account for and need to login? I couldn't come up with that many if I tried!!

 

Nothing personal, but that's insane!! LOL

 

Maybe should create a poll to see what number of passwords is majority that users have?!

  On 19/12/2018 at 18:52, cork1958 said:

Holy crap! 406 websites that you have an account for and need to login? I couldn't come up with that many if I tried!!

 

Nothing personal, but that's insane!! LOL

 

Maybe should create a poll to see what number of passwords is majority that users have?!

Expand  

I'm so sorry. I miss spoke. I just looked and if I remove the 192.168.1.1 passwords I have 485.

 

There is such a poll I created on August 17th 2017 

 

The password Poll

 

 

Well, huh? I some how missed that poll!! :(

 

Just voted on it though. Didn't leave a reply being that it's from last year. I fit in with most of the votes. 20-30 passwords although that may be a high guess, different combinations of same passwords with random gibberish. No option for storing password in your brain though!!

  On 20/12/2018 at 12:24, cork1958 said:

Well, huh? I some how missed that poll!! :(

 

Just voted on it though. Didn't leave a reply being that it's from last year. I fit in with most of the votes. 20-30 passwords although that may be a high guess, different combinations of same passwords with random gibberish. No option for storing password in your brain though!!

Expand  

don't worry, you can still leave a reply, I already bumped it yesterday.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • OBS Studio 31.1.0 Beta 2 by Razvan Serea OBS Studio is software designed for capturing, compositing, encoding, recording, and streaming video content, efficiently. It is the re-write of the widely used Open Broadcaster Software, to allow even more features and multi-platform support. OBS Studio supports multiple sources, including media files, games, web pages, application windows, webcams, your desktop, microphone and more. OBS Studio Features: High performance real time video/audio capturing and mixing, with unlimited scenes you can switch between seamlessly via custom transitions. Live streaming to Twitch, YouTube, Periscope, Mixer, GoodGame, DailyMotion, Hitbox, VK and any other RTMP server Filters for video sources such as image masking, color correction, chroma/color keying, and more. x264, H.264 and AAC for your live streams and video recordings Intel Quick Sync Video (QSV) and NVIDIA NVENC support Intuitive audio mixer with per-source filters such as noise gate, noise suppression, and gain. Take full control with VST plugin support. GPU-based game capture for high performance game streaming Unlimited number of scenes and sources Number of different and customizable transitions for when you switch between scenes Hotkeys for almost any action such as start or stop your stream or recording, push-to-talk, fast mute of any audio source, show or hide any video source, switch between scenes,and much more Live preview of any changes on your scenes and sources using Studio Mode before pushing them to your stream where your viewers will see those changes DirectShow capture device support (webcams, capture cards, etc) Powerful and easy to use configuration options. Add new Sources, duplicate existing ones, and adjust their properties effortlessly. Streamlined Settings panel for quickly configuring your broadcasts and recordings. Switch between different profiles with ease. Light and dark themes available to fit your environment. …and many other features. For free. At all. OBS Studio 31.1.0 Beta 2 changelog: Adjusted volume mixer styling on Classic theme [Warchamp7] Enabled font size option for macOS in appearance settings [gxalpha] Fixed an issue in Beta 1 where the projector menu for disabled preview was incorrect [Warchamp7] Fixed an issue in Beta 1 where opening appearance settings would enable the Apply button [Warchamp7] Fixed an issue in Beta 1 with menu bar padding [Warchamp7] Fixed an issue in Beta 1 with cut off text in Auto-Configuration Wizard [shiina424] Fixed an issue in Beta 1 with tab padding for new UI Appearance options [COOLIGUAY] Fixed an issue in Beta 1 where AMF AV1 B-frames did not work when using CQP [rhutsAMD] Download: OBS Studio 31.1.0 Beta 2 | Portable | ~200.0 MB (Open Source) View: OBS Studio Homepage | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Brave 1.79.119 by Razvan Serea Brave Browser is a lightning-fast, secure web browser that stands out from the competition with its focus on privacy, security, and speed. With features like HTTPS Everywhere and built-in tracker blocking, Brave keeps your online activities safe from prying eyes. Brave is one of the safest browsers on the market today. It blocks third-party data storage. It protects from browser fingerprinting. And it does all this by default. Speed - Brave is built on Chromium, the same technology that powers Google Chrome, and is optimized for speed, providing a fast and responsive browsing experience. Brave Browser also features Brave Rewards, a system that rewards users with Basic Attention Tokens (BAT) for viewing opt-in ads. This innovative system provides an alternative revenue model for content creators and a way to support the Brave community. Brave 1.79.119 changelog: [Security] Added a conditional host check in binding handlers as reported on HackerOne by newfunction. (#46181) Fixed procedural filters not matching against dynamically added child elements. (#46208) Upgraded Chromium to 137.0.7151.68. (#46515) Download: Brave Browser 64-bit | 1.2 MB (Freeware) Download: Brave Browser 32-bit View: Brave Homepage | Offline Installers | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Here's every new AI feature Apple rumored to announce at WWDC 2025 by Hamid Ganji While Apple's WWDC event kicks off on June 9, Bloomberg's Mark Gurman has released a detailed report about every new AI feature Apple might unveil at the event. One of the most notable AI-related announcements at this year's WWDC is the Translate app. According to Gurman, Apple aims for a "systemwide push into translation" in iOS 26 while giving an AI boost to its Translate app. The app is expected to function as an Apple Intelligence feature and will be integrated into the operating system. The Translate app, initially designed for translating text, voice, and conversations, will focus on live translation of phone calls and text messages in iOS 26. Gurman also added that Apple is working on translating live conversations for AirPods wearers. Apple has a slew of AI-related announcements at WWDC 2025. For example, the iPhone maker reportedly allow third-party developers to access its Foundation Models to build AI features. Foundation Models are a suite of generative AI models behind Apple Intelligence features, including text summarization, Writing Tools, and Genmoji. Speaking of Genmoji, Gurman claims the feature in iOS 26 allows users to create a Genmoji by combining a pair of existing standard emoji. The Shortcuts app in iOS 26 also gets a touch of Apple Intelligence, allowing users to seamlessly create quick shortcuts for various actions using AI. Apple has seemingly prepared an upgraded version of the Foundation Models for both on-device and cloud use. These models will be announced at the WWDC, but developers can only access the on-device version. Today's report suggests that Apple will also introduce a new version of Xcode that taps into third-party LLMs. The feature is being tested internally using Claude models. According to Gurman, Apple's revamped Calendar app won't make it to this year's software and will debut on iOS 27 and macOS 27. Moreover, Apple's new Health app with AI recommendations has hit delays and won't be announced at the upcoming WWDC. The revamped app will be released at the earliest by the end of next year. Apple's battery optimization feature, which uses AI to save power on iPhones, may debut later this year with the iPhone 17 Air. Finally, Gurman says Apple is in talks with Google to add Gemini to iPhones as an alternative to OpenAI's ChatGPT. However, the collaboration won't be announced at this year's WWDC. Companies await the final ruling on Google's search deal with Apple.
    • WYSIWYG Web Builder 20.2.1 by Razvan Serea Web Buialder is a WYSIWYG (What-You-See-Is-What-You-Get) program used to create complete web sites. WYSIWYG means that the finished page will display exactly the way it was designed. The program generates HTML (HyperText Markup Language) tags while you point and click on desired functions; you can create a web page without learning HTML. Just drag and drop objects to the page position them "anywhere" you want and when youre finished publish it to your web server (using the build in Publish tool). Web Builder gives you full control over the content and layout of your web pages. One Web Builder project file can hold multiple web pages. Desktop publishing for the web, build web sites as easy as Drag & Drop "One Click Publishing" No FTP program needed. No special hosting required, use with any Hosting Service! Easily create forms using the built-in Form Wizard plus Form validation tools and built-in CAPTCHA. Advanced graphics tools like shapes, textart, rotation, shadows and many other image effects. Fully integrated jQuery UI (Accordion, Tabs etc), animations, effects and built-in ThemeRoller theme editor. Google compatible sitemap generator / PayPal eCommerce Tools Many navigation tools available: Navigation bars, tab menus, dropdown menus, sitetree, slidemenus. Built-in Slide Shows, Photo Galleries, Rollover images, Banners etc. Support for YouTube, Flash Video, Windows Media Player and many other video formats. Unique extension (add-on) system with already more than 250 extensions available! Create HTML5 / CSS3 websites today HTML5 document type (optimized HTML5 output). HTML5 audio/video and YouTube HTML5 support. HTML5 forms: native form validation, new input types and options, web storage. HTML5 canvas and svg support in shapes and other drawing tools. CSS3 @font-face. Use non web safe fonts in all modern browsers. CSS3 opacity, border radius, box shadow. CSS3 gradients. Add cool gradient effects using native CSS3 (no images). CSS3 navigation menu. Create awesome menus without using JavaScript or images. CSS3 animations and transitions. Including support for 2D and 3D transforms! Features for advanced users: Login Tools/Page Password Protection. Built-in Content Management System with many plug-ins (guestbook, faq, downloads, photo album etc). Add custom HTML code with the HTML tools. JavaScript Events: Show/hide objects (with animation), timers, move objects, change styles etc. Layers: Sticky layer, Docking layer, Floating layer, Modal layer, Anchored layer, Strechable layer and more! jQuery Theme Manager, create your own themes for the built-in jQuery UI widgets. Style Manager (global styling, H1, H2, H3 etc). Master Frames and Master Objects: reuse common element in your website. and much more! WYSIWYG Web Builder 20.2.1 changelog: Improved: Images in the properties of Photo Gallery, Photo Grid, Photo Collage and Slide Show can now be re-arrange using drag & drop. Improved: Default aspect ratio of HTML5 audio Fixed: Issue with list item icon offset in workspace. Fixed: 'Edit' button text in Login Admin cannot be changed. Fixed: Issue with Card max-width size calculation in breakpoints Fixed: Issue with (fixed) Layout Grid column height in breakpoints. Download: WYSIWYG Web Builder 64-bit | 30.1 MB (Shareware) Download: WYSIWYG Web Builder 32-bit | 28.0 MB Screenshot: >> Click here << Link: Home Page | Templates | Free extras/addons | Changelog Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Year In
      Vladimir Migunov earned a badge
      One Year In
    • One Month Later
      daelos earned a badge
      One Month Later
    • Week One Done
      daelos earned a badge
      Week One Done
    • Mentor
      Karlston went up a rank
      Mentor
    • One Month Later
      EdwardFranciscoVilla earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      494
    2. 2
      snowy owl
      252
    3. 3
      +FloatingFatMan
      250
    4. 4
      ATLien_0
      225
    5. 5
      +Edouard
      183
  • Tell a friend

    Love Neowin? Tell a friend!