3 ms·
Technically yes, but the main tricks for phishing OTP codes from phones now don't work with those apps, the current ones involve getting people to install an ap
by faceplanted 7y ago
Technically yes, but the main tricks for phishing OTP codes from phones now don't work with those apps, the current ones involve getting people to install an app and getting them to give the app SMS permissions, which there isn't a permission for getting data from ubikey apps unless they go through the phone's storage which is a problem encryption and fingerprint scanners can fix. And calling someone and telling them you accidentally put their number into a site an are trying to recover their account so could you please read me the number you get texted, which doesn't work for UBIKey since you know exactly what that code is for and they can't have been the previous owner of your phone number or accidentally sign you up to that.
There's plenty of others obviously, phishing is an infinite sea of crazy ideas, but that's a few huge ones gone.
- tialaramex 7y agoNo. There are ready to go out of the box proxy tools that rely only on you thinking this proxy is really the site you wanted, and then your TOTP, SMS message, any of these third rate second factors get phished. The reason Security Keys (ie WebAuthn/U2F) doesn't get phished in this scenario is that the human's worthless opinion about whether this is the correct site isn't used by these technologies. Your WebAuthn credentials submitted to the utterly convincing phishing site fake-bank.example don't work for your real-bank.example login and the phishing fails.