UK trio pleads guilty to operating $10M MFA bypass biz

Discussion in 'malware problems & news' started by stapp, Sep 4, 2024.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,692
    Location:
    UK
    https://www.theregister.com/2024/09/03/uk_trio_pleads_guilty_mfa_bypass/
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I already mentioned this in another thread, but this showcases why TOTP is pretty much a joke.

    A good 2FA system should not be prone to phishing. The main problem is that 2FA based on TOTP does not actually communicate with the password manager or 2FA app, in other words it doesn't communicate with the PC. If this was a requirement, then phishing wouldn't work, at least not via fake websites, because only the real website would be able to ask for the OTP (one time password).
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.