7 ms·
> and phishing shouldn't work if something like TOTP is implemented correctly TOTP codes can be phished. Hardware-based 2FA is a different matter, but SMS and
by chimeracoder 6y ago
> and phishing shouldn't work if something like TOTP is implemented correctly
TOTP codes can be phished. Hardware-based 2FA is a different matter, but SMS and TOTP 2FA doesn't fully protect against phishing.
- formercoder 6y agoOnly for high value targets right? Takes some work to spoof.
- strombofulous 6y agoTypically this takes enough work that it has to be at least somewhat targeted but even some rando with just a few thousand dollars in their account would probably be a large enough target because it doesn't take super long
- chimeracoder 6y agoDepending on the method, it doesn't have to be targeted to the user, just to the platform. For a platform like Robin Hood, most accounts contain enough money that even one account could pay off for the effort.
- bawolff 6y agoNo. phising sms/totp tokens works the same as normal phising. You need U2F to protect against phising. The complex attack you are probably thinking of is sim swapping which is a bit different than phising.
- formercoder 6y agoOh yeah I was thinking of sim swapping. Thanks.
- zenexer 6y agoTOTP gets a little tricky when it comes to phishing, but only because most phishing attacks that target casual users (rather than spear phishing attacks) aren't capable of logging in immediately. Naturally, that would change if enough people started using TOTP, but for now, TOTP is enough to avoid becoming low-hanging fruit. Of course, if you're a high-value target or work for a company that's likely to be targeted by spear-phishing campaigns, you should be using FIDO2. (Don't target U2F, as there are newer, backward-compatible specifications.)
- Thorrez 6y agoYeah most phishing attacks can't auto login, but there is an open source tool for doing it: https://github.com/kgretzky/evilginx2 https://github.com/kgretzky/evilginx2
- zenexer 6y agoWhen properly implemented, TOTP codes are difficult to phish without tipping off the user because codes can't be reused. The spec requires that the service not allow code reuse within a given time window--although not all websites comply with that, unfortunately. Assuming the implementation is correct, that means the phishing page has to convince the user that it's acceptable to enter their TOTP code twice, and they have to log in very quickly. Most (non-spear-) phishing pages are basically just forms that email victims' credentials to the attacker; they aren't capable of logging into someone's account, let alone multiple accounts without tipping off someone on the security team. If you get a message indicating your password was invalid, you're probably not going to pay a whole lot of attention to it--even with a password manager, it's a common message to receive on financial sites. Some go out of their way to impede password managers because they think that's a good security practice. If you get a message indicating the 6-digit code you entered is invalid, that should be a lot more concerning to you, and you should immediately ensure that nobody has logged into your account. If you can hold out for however long the site will accept the code (usually 60 seconds, but some sites have a larger window), you're good. Of course, none of these "ifs" exist with FIDO2 and U2F, which is what everyone should be using instead. If you're in charge of security for a website, please offer FIDO2 and/or U2F.
- tedunangst 6y agoYour phish site says it has an important message and demands a TOTP code, then once entered it says "important: thanks for being our customer". User thinks this is dumb, closes tab. No need to enter code twice.
- zenexer 6y agoMost people who bother with TOTP are a little more security-conscious. If you’re attempting to phish random targets, rather than spear phishing, you’re probably not going to bother with all that.
- Thorrez 6y ago>If you get a message indicating the 6-digit code you entered is invalid, that should be a lot more concerning to you I could type the 6-digit code incorrectly just as well as I could type the password incorrectly. Additionally, some sites might check both the password and the 2FA code simultaneously as a security mechanism to prevent attackers learning if the password is correct. Additionally, the phishing page could simply redirect the user to the real site. The user is likely already logged in to the real site, so it will appear to the user as if the user just performed a successful login. If the user isn't logged in, it will seem like some type of site glitch, and I've experienced glitches like that myself.