Earlier quoted context omitted.
This assumes that the banking app receives push data about the transaction by the bank, and simply has an "approve" button A simple 2FA app like Authy/Aegis that produces a number has the same problems as the keyfob. The threat model is: malicious actor posing as the bank website, but legitimate keyfob or legitimate app. With the keyfob, the website intercepts a valid password and a valid 2FA code; with the app, noth…
> with the app, nothing happens because it doesn't receive push data from the true bank. I don't see how that feature matters to a man in the middle attack during logon, since: 1. User opens web browser at a phishing site, which is masquerading as their bank, and starts the login process. 2. Phishing site interacts with bank. 3. Bank sends push-notification to the phone# that's on-file for that user: "Hey, that you l…
The Yubikey Is the Digital Seatbelt We Need
71–73 of 73 posts
Re: The Yubikey Is the Digital Seatbelt We Need
#72I recommend Hack Recovery KEVIN M HACKER to anyone who needs this service. I decided to get into crypto investing and lost my crypto to an investor late last year. The guy who was supposed to manage my account was a fraud the whole time. I invested $180,000 and at first my read and profit margins looked good. I got worried when I couldn't make withdrawals and realized I had been tricked. I found some testimonials that people had to say about Hack Recovery KEVIN M HACKER and how helpful it was in getting their money back. I immediately contacted him via. Email: kevinmitnick100@hackermail.com, Telegram @Kelvinmhacker or WhatsApp via: +1-256-956-4498, and I’m sure you will be happy you did.
Re: The Yubikey Is the Digital Seatbelt We Need
#73Bought yubikey on a sale a few years ago. Not usable for mobile in that model (4?) (but I knew it in advance of course). Then found out that most of the sites don't accept it in the Firefox, only in the Chrome and its clones. And so it is collecting dust somewhere in my old apartment.