3 ms·
You can phish someone by getting their username/password, using that to log in to the targetted service, and then convincing the user to type their 6 digit 2FA
by ajdlinux 8y ago
You can phish someone by getting their username/password, using that to log in to the targetted service, and then convincing the user to type their 6 digit 2FA code into the phishing page.
If they plug in their hardware token, the browser will give the token the real domain name which won't match the legitimate domain name, so the attacker can't use the response from the key to log in.
- akavel 8y agoThanks! I imagine instead of via USB to hardware token, the query could theoretically go via my PC's Bluetooth to my phone?
- bumholio 8y agoA phishing attack can often involve local compromise, making the user install malware etc. In that case, it's a simple attack variant to spoof the USB communication and get valid credentials whenever the user uses the key.
- ajdlinux 8y agoIt can, but at that stage it's no longer a phishing attack, it's a full remote compromise. Your average phishing attack is just a web page.