2FA Flaws - Tagged - Security Boulevard The Home of the Security Bloggers Network Thu, 28 Mar 2024 18:46:58 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.3 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png 2FA Flaws - Tagged - Security Boulevard 32 32 133346385 Apple OTP FAIL: ‘MFA Bomb’ Warning — Locks Accounts, Wipes iPhones https://securityboulevard.com/2024/03/mfa-bomb-apple-otp-richixbw/ Thu, 28 Mar 2024 18:46:58 +0000 https://securityboulevard.com/?p=2013312 Multiple, unskippable notifications

Rethink different: First, fatigue frightened users with multiple modal nighttime notifications. Next, call and pretend to be Apple support.

The post Apple OTP FAIL: ‘MFA Bomb’ Warning — Locks Accounts, Wipes iPhones appeared first on Security Boulevard.

]]>
2013312
Telegram Privacy Nightmare: Don’t Opt In to P2PL https://securityboulevard.com/2024/03/telegram-privacy-nightmare-p2pl-richixbw/ Tue, 26 Mar 2024 17:29:25 +0000 https://securityboulevard.com/?p=2012982 Scary skeletons

Scary SMS shenanigans: Avoid Telegram’s new “Peer-To-Peer Login” program if you value your privacy or your cellular service.

The post Telegram Privacy Nightmare: Don’t Opt In to P2PL appeared first on Security Boulevard.

]]>
2012982
FCC’s Got New Rules for SIM-Swap and Port-Out Fraud https://securityboulevard.com/2023/11/fcc-new-rules-sim-swap-port-out-richixbw/ Mon, 20 Nov 2023 15:33:00 +0000 https://securityboulevard.com/?p=1999643 A blown out picture of FCC chairwoman Jessica Rosenworcel

Too many times: Federal Communications Commission shuts stable door after horse bolted. But chairwoman Jessica Rosenworcel (pictured) was hoping it would save us.

The post FCC’s Got New Rules for SIM-Swap and Port-Out Fraud appeared first on Security Boulevard.

]]>
1999643
Teenage Hackers Must be Stopped: US DHS’s CSRB Report https://securityboulevard.com/2023/08/lapsus-dhs-csrb-sms-richixbw/ Fri, 11 Aug 2023 15:16:16 +0000 https://securityboulevard.com/?p=1984691 DHS secretary Alejandro Mayorkas

2FA SMS FAIL: Lapsus$ social engineers exploited weak two-factor authentication. Something must be done! (Well, this is something.)

The post Teenage Hackers Must be Stopped: US DHS’s CSRB Report appeared first on Security Boulevard.

]]>
1984691
FINALLY! Google Makes 2FA App Useable — BUT There’s a Catch https://securityboulevard.com/2023/04/google-2fa-app-sync-richixbw/ Tue, 25 Apr 2023 17:39:06 +0000 https://securityboulevard.com/?p=1973044

2FA OTP ASAP? Google Authenticator app now syncs your secrets: No stress if you break your phone.

The post FINALLY! Google Makes 2FA App Useable — BUT There’s a Catch appeared first on Security Boulevard.

]]>
1973044
Two Factor? https://securityboulevard.com/2020/03/two-factor/ Wed, 04 Mar 2020 20:00:00 +0000 http://securityboulevard.com/?guid=e16075c8c36e4d6031d910556b664d2a

The post Two Factor? appeared first on Security Boulevard.

]]>
1838736
Instagram 2FA Bypass, A Tale of Superlative Bug Hunting Skills & Indolent Multi-Factor Authentication https://securityboulevard.com/2019/07/instagram-2fa-bypass-a-tale-of-superlative-bug-hunting-skills-indolent-multi-factor-authentication/ Fri, 19 Jul 2019 17:00:00 +0000 http://securityboulevard.com/?guid=92eabc9f695be5687b93a33ed3b2b530

Via Tara Seals writing at the Threatpost Blog, detailing the highly competent bug hunting skill set of Laxman Muthiyah, examining - if you will - the lackadaisical 2FA data flow promulgated by Facebook, Inc. (Nasdaq: FB) on the company's owned Instagram.

"Independent researcher Laxman Muthiyah took a look at Instagram’s mobile recovery flow, which involves a user receiving a six-digit passcode to their mobile number for two-factor account authentication (2FA). So, with six digits that means there are 1 million possible combinations of digits making up the codes." - Via Tara Seals writing at the Threatpost Blog

The post Instagram 2FA Bypass, A Tale of Superlative Bug Hunting Skills & Indolent Multi-Factor Authentication appeared first on Security Boulevard.

]]>
1813902