Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The attacker could proxy the 2FA request from the real site using the password you enter and therefore you wouldn't be protected.


Yes, you can MITM 2FA, but you can't timeshift 2FA.


Right, they could have access to your account, but not full access. A good website will ask for 2FA again if a user tries to do something destructive (like change password, email, or disable 2FA). They wouldn’t be able to do those things.


> A good website will ask for 2FA again if a user tries to do something destructive (like change password, email, or disable 2FA). They wouldn’t be able to do those things.

The page mocking the login page where you need to answer the 2FA will simply phish your 2FA then, after a little delay pretending there's some lag, would say "wrong code, please try again". Now the person enters a second 2FA (which, due to the delay, would be different than the first one).

As I've just commented in a top-level comment: I've seen sites using a 72 hours delay before any destructive change can be made, coupled with the sending of an email containing a link allowing to unilaterally prevent the change.

I've also seen sites using two 2FA (TOTP style), one for login, one for any setup/destructive change. And there are sites using both techniques.

It's not 100% foolproof but it's better than "one 2FA phished and it's game over".


Yes, that’s basically the author’s point. But it does protect you against someone trying to use your password on another site.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: