Earlier quoted context omitted.
> convince a user to enter their google 2fa code into a site that isn't obviously google? if the BAD site itself looks legit, and has convinced a user to do the initial login in the first place, they won't hesitate to lie and say that this 2-factor code is part of their partnership with google etc, and tells you to trust it. A normal user doesn't understand what is a 2factor code, how it works, and such. They will ea…
What I don't understand is how the site will send the 2FA code request to the bad actors phone, instead of the real users phone? Is this not part of what makes it more secure than a text or email? Wouldn't the bad actor need to be logged into the authenticator as the user your trying to hack?
the 2FA code in this case is in the email, not via an app. This email is triggered by BAD on their end, but it is sent by GOOD.
If the 2fa is _only_ via the authenticator app, then the BAD will need to convince the user to type in that 2fa code from the app into the BAD site (which is harder, as nobody else does this, so it should raise suspicions from the user at least).