[HN Gopher] Phishing 2FA 25 years ago
___________________________________________________________________
Phishing 2FA 25 years ago
Author : pbear2k23
Score : 34 points
Date : 2023-10-06 18:34 UTC (4 hours ago)
(HTM) web link (twitter.com)
(TXT) w3m dump (twitter.com)
| br1 wrote:
| The old solutions to phishing, education and weak 2fa, are in the
| way of the new and improved solutions, FIDO, passkeys. Nobody
| wants to admit that the old ways were lacking. They were hipped
| too hard. It's like when new health guidelines appear and
| contradict the old ones.
| kstrauser wrote:
| Me! _waves hand in the air_ I admit the old ways were lacking.
| We just didn 't have a lot of better alternatives at the time.
| SMS 2FA beats no 2FA. TOTP beats SMS 2FA. FIDO/passkeys/etc
| beat TOTP.
|
| We've made a lot of progress as new methods and technologies
| have become available.
| lcnPylGDnU4H9OF wrote:
| https://en.wikipedia.org/wiki/Universal_2nd_Factor
|
| https://www.yubico.com/
|
| A 2FA _token_ is simply another "thing you know". A plugged-in
| USB dongle is actually "something you have". (Although,
| technically, it's still "something you know" because it has a
| secret key; it's _considerably_ more difficult to phish this
| key.)
| TestingTest5 wrote:
| Right now the most basic USB-C Yubico Key-Dongle goes for
| around $80 (considering taxes and shipping in Europe). As
| yubico state themselves, you really need 2 dongles just in
| case.
|
| Most people are not paying $160 for this, period, when 2FA and
| passkeys are a "good enough" thing.
| throw0101c wrote:
| In addition to tokens there were software-only solutions:
|
| * https://en.wikipedia.org/wiki/S/KEY (RFC 1760)
|
| * https://en.wikipedia.org/wiki/OPIE_Authentication_System
|
| * https://en.wikipedia.org/wiki/OTPW
| Dachande663 wrote:
| Do people not track the last used time window of a TOTP and
| require a newer window for subsequent events? Most libraries I've
| used come with that as part of the interface.
| gs17 wrote:
| It wouldn't help here, the OTP was only actually used when he
| received the phished login. The fake site didn't submit it to
| the AOL servers.
___________________________________________________________________
(page generated 2023-10-06 23:01 UTC)