3 ms·
2fa would have protected him.
by gonyea 9y ago
2fa would have protected him.
- AgentME 9y agoIs 2fa that big of a deal to a dedicated attacker who gets the victim to enter their info into a phishing page? (Just thinking of passcode-style 2fa, not usb key 2fa.) The attacker just has to forward the victim's login info to a login page, and then if the attacker gets a 2fa prompt, they prompt the victim with a 2fa prompt and then forward the victim's answer immediately. I understand a lot of attackers don't bother since there's plenty of easier victims without 2fa, but if they're targeting a specific individual, it's not that much more work to make their attack work on 2fa too.
- aiiane 9y agoThat's why U2F is a better alternative - it avoids the phishing issue as well as the password reuse issue.
- technion 9y agoI've had a number of successes in phishing tests against 2FA protected Office 365 services. https://github.com/technion/3652fa https://github.com/technion/3652fa