I don't know whether it amounts to a security vulnerability, but it certainly makes it that little bit weaker.
I know someone whose 2-factor phone authentication was hacked...
71–75 of 75 posts
Re: I know someone whose 2-factor phone authentication was hacked...
#72Earlier quoted context omitted.
The attack was on a phone call message for 2-factor authentication "Your one time password is XXXXXX. Please use this to login now" not an RSA token.
I believe the OP is referring to http://www.finextra.com/news/fullstory.aspx?newsitemid=22375
When RSA was compromised, accounts in which RSA was used as an additional factor remained protected by their remaining uncompromised factors - allowing time to replace the RSA factor.
Re: I know someone whose 2-factor phone authentication was hacked...
#73Two factor authentication is still, in my opinion, the strongest way to go. This case is really the phone company's fault, maybe they'll learn from this and start teaching the customer support reps what the difference is between a correct password and an incorrect password.
(TL;DR at bottom) I see a lot of hacks of voice mails and then requests for Google to use the second factor to reset the account...all by baddies. Who then proceed to take over the account. So, it seems to me that it's worse than having no second factor at all. After all, why is it stronger to use two factors than just using a strong password from your laptop or personal devices - without ANY backup contact informati…
I agree with you totally. A second authentication that is much weaker than the first (prone to social engineering or even googling like the endemic first name of your favorite uncle questions) can be worse than just having one strong authentication. For some reason many companies think that building a bridge out of very many weak components makes a strong bridge. That is not true though, you have a weak bridge in the end.
Re: I know someone whose 2-factor phone authentication was hacked...
#74Relatedly, it is possible to read the 2FA SMS message on android without pattern unlocking the phone -- it appears in the notification bar briefly. I don't know whether it amounts to a security vulnerability, but it certainly makes it that little bit weaker.