How Hackers Bypass Gmail 2FA at Scale


Recommended Posts

  Quote

 

If you’re an at risk user, that extra two-factor security code sent to your phone may not be enough to protect your email account.

Hackers can bypass these protections, as we’ve seen with leaked NSA documents on how Russian hackers targeted US voting infrastructure companies. But a new Amnesty International report gives more insight into how some hackers break into Gmail and Yahoo accounts at scale, even those with two-factor authentication (2FA) enabled.

They do this by automating the entire process, with a phishing page not only asking a victim for their password, but triggering a 2FA code that is sent to the target’s phone. That code is also phished, and then entered into the legitimate site so the hacker can login and steal the account.

The news acts as a reminder that although 2FA is generally a good idea, hackers can still phish certain forms of 2FA, such as those that send a code or token over text message, with some users likely needing to switch to a more robust method.

“Virtually in that way they can bypass any token-based 2FA if no additional mitigations are implemented” Claudio Guarnieri, a technologist at Amnesty, told Motherboard in an online chat.

2FA is adding another layer of authentication onto your account. With token-based 2FA, you may have an app that generates a code for you to enter when logging in from an unknown device, or, perhaps most commonly, the service will send a text message containing a short code that you then type into your browser.

 

Expand  

 

https://motherboard.vice.com/en_us/article/bje3kw/how-hackers-bypass-gmail-two-factor-authentication-2fa-yahoo

 

In my opinion, this is another benefit of a password manager like lastpass which autofills passwords. If you log in using a password manager it will bot autofill (at least not automatically) your password into a fake website. It goes by the domain. So it will auto fill https://mail.google.com but not https://mail.gooogle.com . So when it doesn't auto fill my passwords, or show a matching passcard(s) to the website, I take one last look at the address bar.

  On 19/12/2018 at 16:45, cork1958 said:

Personally, wouldn't/don't trust a password manager anymore than I trust Trump to tell the truth!! :)

Expand  

I just don't think I can get creative enough to come up with unique passwords for each of the 406 websites. That being said after the last lastpass outage I do keep a currentish import in keepass on 2 disconnect flash drives.

  On 19/12/2018 at 16:48, warwagon said:

I just don't think I can get creative enough to come up with unique passwords for each of the 406 websites. That being said after the last lastpass outage I do keep a currentish import in keepass on 2 disconnect flash drives.

Expand  

Holy crap! 406 websites that you have an account for and need to login? I couldn't come up with that many if I tried!!

 

Nothing personal, but that's insane!! LOL

 

Maybe should create a poll to see what number of passwords is majority that users have?!

  On 19/12/2018 at 18:52, cork1958 said:

Holy crap! 406 websites that you have an account for and need to login? I couldn't come up with that many if I tried!!

 

Nothing personal, but that's insane!! LOL

 

Maybe should create a poll to see what number of passwords is majority that users have?!

Expand  

I'm so sorry. I miss spoke. I just looked and if I remove the 192.168.1.1 passwords I have 485.

 

There is such a poll I created on August 17th 2017 

 

The password Poll

 

 

Well, huh? I some how missed that poll!! :(

 

Just voted on it though. Didn't leave a reply being that it's from last year. I fit in with most of the votes. 20-30 passwords although that may be a high guess, different combinations of same passwords with random gibberish. No option for storing password in your brain though!!

  On 20/12/2018 at 12:24, cork1958 said:

Well, huh? I some how missed that poll!! :(

 

Just voted on it though. Didn't leave a reply being that it's from last year. I fit in with most of the votes. 20-30 passwords although that may be a high guess, different combinations of same passwords with random gibberish. No option for storing password in your brain though!!

Expand  

don't worry, you can still leave a reply, I already bumped it yesterday.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.