3 ms·
It’s worth pointing out that if you are not the one initiating the call, then this is a legitimate attack vector, and not just via SMS text message or email two
by smaccona 5y ago
It’s worth pointing out that if you are not the one initiating the call, then this is a legitimate attack vector, and not just via SMS text message or email two factor but also any type of OTP. The attack goes like this: (1) given that the whole point of two-factor auth is to prevent access to your account in the event that your primary authentication tokens (usually a username and password) are compromised, let’s assume for this attack that a bad actor already knows your username and password. (2) the attacker calls you up and says “this is <your bank>”, then (3) the attacker logs into your account with the username and password they already know (4) this either triggers an email or text message with the second factor, or if you use a hardware token or an app then the code is available there. Either way, the attacker requests you to read back the code over the phone (5) the attacker uses this secondary code to gain access to your account, and can then take any action including changing your password and 2nd factor setup. I think this is the reason security teams set up these messages to say things like “NEVER share this code!” and the like.