rakkhi,

Pretty cool #phishing attack after the #okta one:

https://retool.com/blog/mfa-isnt-mfa/

Great reason to use #u2f that cannot enter the 2nd factor into a dodgy site

https://rakkhi.substack.com/p/how-to-make-phishing-impossible

mdh,

@rakkhi this has been telegraphed for a long time already but is the first case I recall seeing this actually used.

It’s going to be very difficult for the human brain to grapple with the idea of receiving a call from the right number with the right voice saying the right things and to still have to contend with the fact that maybe none of it is real.

rakkhi,

deleted_by_author

  • Loading...
  • mdh,

    @rakkhi it’s nice in the sense that it doesn’t rely on the same signals as the brain and can’t be tricked in the same way but damn… I can absolutely do some real damage if I can call you and convince you that I’m your boss and I need you to do something for me urgently.

    rakkhi,

    deleted_by_author

  • Loading...
  • mdh,

    @rakkhi there are a whole range of attacks I can pull off where I don’t need to steal your creds because now I can just convince you to do it on my behalf with this capability

    rakkhi,

    deleted_by_author

  • Loading...
  • mdh,

    @rakkhi I don’t see how that helps in a whole range of scenarios that fundamentally aren’t authN/Z problems any more.

    The example I gave before of a high pressure deep fake call to your accounts department where I essentially do the phone version of a BEC scam is going to continue working just fine because the right person is doing the right tasks for their job, they just happen to be doing them for the wrong reason and under false pretences.

    The “correct” thing to do in that scenario is to call them back on a known number to verify but if you called me on a known number and you sound like my boss I wouldn’t think to do that and at no point is 2FA going to solve that situation. I don’t think more tech is the magic bullet here to be fair.

    mdh,

    @rakkhi or to use a more timely example… we don’t have all the details here yet but it’s certainly not obvious from what we do know currently that U2F solves this attack at all https://www.engadget.com/hackers-claim-it-only-took-a-10-minute-phone-call-to-shutdown-mgm-resorts-143147493.html

    mdh,

    @rakkhi put me through to accounts, I need to get this invoice paid immediately! We are going to lose the deal otherwise

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • tacticalgear
  • JUstTest
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • megavids
  • lostlight
  • All magazines