4 ms·
You can't guess the 2FA code. It changes faster than you could ever attempt to test all combinations.
by SilverRed 5y ago
You can't guess the 2FA code. It changes faster than you could ever attempt to test all combinations.
- KingMachiavelli 5y agoBut you could try ~100 password variations and then attack the 2FA. Up until recently SMS 2FA could be broken for $10 because one VOIP provider allowed number registration on any number. If you can filter 10,000 accounts down to 100 with known passwords, now you just have to bypass 2FA on 100 accounts.
- alienalp 5y agoHow can you register a number if its already registered?
- patmcc 5y agoA common service offered (I think required to be offered, actually) by telephone service providers is "number porting" - where you switch providers but keep the same number, because people don't like changing phone numbers more than they have to. It used to be this didn't have any real backend checks, so you could effectively steal someone's number, at least temporarily.
- stef25 5y ago> Up until recently SMS 2FA could be broken for $10 because one VOIP provider allowed number registration on any number. Surely not?
- KingMachiavelli 5y ago> "I used a prepaid card to buy their $16 per month plan and then after that was done it let me steal numbers just by filling out LOA info with fake info," Lucky225 added, referring to a Letter of Authorization, a document saying that the signer has authority to switch telephone numbers. From 2021: https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-16-dollars-sakari-netnumber https://www.vice.com/en/article/y3g8wb/hacker-got-my-texts-1... EDIT: yea it's not 'registering' the number but rather rerouting a copy of all messages to another number.
- tinus_hn 5y agoIt doesn’t matter that the code changes, each guess has a 1/1000000 chance of being the right code. Yes you can’t guarantee you’ll find the code in 1000000 tries, but you still only need to do half of that to have 50% chance of a match.
- foxpurple 5y agoIf someone attempts 500,000 failed 2FA attempts on an account, I think its safe to lock that account/take extra steps.