5 ms·
If it’s a website which supports API key or any token of sorts (without expiry or long expiry), they could do some real damage even if they can’t use the 2FA ag
by 8ytecoder 6y ago
If it’s a website which supports API key or any token of sorts (without expiry or long expiry), they could do some real damage even if they can’t use the 2FA again. Another thing would be to disable 2FA.
All they have to do to achieve this is to use the phished credentials to immediately login with the original site, trigger 2FA and then show a field to capture it and pass along. Then capture all the cookies.
The best defense against phishing is to use a password manager that does domain matching.
- cutemonster 6y agoAny such password manager you like? Didn't know they could do domain matching
- CamJN 6y agoNot the person you asked, but: 1Password which I like, and Lastpass which I don't, both do domain matching in the browser extension. All iOS password managers that integrate into the system do domain matching as well.
- cutemonster 6y agoThanks, In addition to that, now I noticed that in the blog post: > I recommend the open source Bit Warden. A password manager stores your passwords. But it also stores the web address of site’s login page. If you visit githud, the password manager won’t prompt you to use the login details for github