4 ms·
I work in the industry if it wasn't obvious though for years now nothing to do with phishing but I do have some experience shall we say. 1. Building a phishing
by CyberRage 5y ago
I work in the industry if it wasn't obvious though for years now nothing to do with phishing but I do have some experience shall we say.
1. Building a phishing page and can accept 2FA and in real time(remember code is useless after 30 sec) logs in to an account is much harder. most attacks are low quality junk.
2. From a detection standpoint, this is awesome. the attacker has to log in real-time. he will likely send that link to hundreds of people = good telemetry to detect anomalies\fraudulent logins.
3.* Another pain I remember observing was regarding the login process itself. Websites tend to change their log in UI\processes, different websites have different layouts.
This makes it frustrating and tedious maintain, bank changes the login prompt, attacker has to modify code to accommodate that.
4. Data doesn't lie, it is not bulletproof but it does offer significantly higher level of protection. saw that in actual enterprise with my own eyes.
- toast0 5y agoSure, it raises the bar, maybe I should have said it's not entirely effective, rather than it'd not effective. Long story short, if you want your corporate logins to not get phished, 2fa with codes (or push to accept in an app) isn't sufficient, although it may reduce the rate. It does nearly eliminate other classes of attack (depending on details: if you're using six digit codes, 1 in 1M isn't zero; if you're using app to accept/deny, some users will say yes when it wasn't actually them)
- CyberRage 5y agoso you're suggesting that someone is going to attempt to guess a 6 digit code? this is not offline brute-force, you're not going to iterate over thousands of codes... Passwords are permanent, that's the main difference. the code is only relevant to 30 secs after that it is useless. passwords are always useful because they never change. Also people tend to re-use or slightly modify their password. with TOTP codes, the previous code doesn't tell you anything regarding the next code.
- toast0 5y ago> so you're suggesting that someone is going to attempt to guess a 6 digit code? Yeah, what else are you going to do when you get a 2fa prompt that you're not prepared to phish? It's unlikely to be right, and you only get a couple tries, but just because it's unlikely to be right doesn't mean it won't be sometimes. And you probably already blew your cover getting to the prompt, may as well make a go.