4 ms·
Not surprised. I submitted a report and POC of an oauth2 vulnerability that they deemed as a low priority. Robinhood users are highly susceptible to phishing a
by lovetocode 6y ago
Not surprised. I submitted a report and POC of an oauth2 vulnerability that they deemed as a low priority. Robinhood users are highly susceptible to phishing attacks. Even 2FA is vulnerable if the attacker is fast enough.
- CameronNemo 6y agoCan you explain the 2FA risk?
- Xavdidtheshadow 6y agoAssuming they're talking about TOTP, the 6-digit codes that are valid for 30 seconds: If I'm fishing you and get you to type your password into fakegoogle.com, I'll try to use it with real google immediately. If they send me a 2FA error (and I've got a semi-sophisticated phishing operation) fakegoogle will show you a an input field for that 6 digit code (just like real google). Then I've got a few seconds to send that to $site as well. It's a tighter timing window, but it's likely at this point that I'm into your account. This sort of attack isn't possible with a hardware key, since it only works on the original domain (which presumably I don't control). Does that make sense?
- im3w1l 6y agoAh, I didn't know hardware keys are domain-bound that's cool. Do they open an encrypted tunnel directly to the server?
- Xavdidtheshadow 6y agoNope, no tunnel or anything. When you touch the yubikey, it does some math on-device and "types" out a long string that can be mathematically validated with the shared secret the site stored when you set it up. It's an open standard, so you can read all about it: https://webauthn.guide/ https://webauthn.guide/
- CameronNemo 6y agoSo the entire attack is premised on me navigating to a fake robinhood domain and entering my credentials? Seems like good password manager hygiene (which checks the domain name before filling credentials) can help prevent this from happening.
- Xavdidtheshadow 6y agoCorrect, something that verifies the domain before pasting goes a long way! Unless it doesn't auto-fill, but it looks right, so you paste it anyway.
- lovetocode 6y agoI agree with you but there are a lot of technologically naive people out there.
- lovetocode 6y agoI don’t even know if I’m allowed to disclose it. My bounty is closed but I am not sure if they fixed it.