Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Phishing Attack Bypasses Two-Factor Authentication
Newest First  |  Oldest First  |  Threaded View
TextPower
100%
0%
TextPower,
User Rank: Strategist
5/12/2018 | 10:29:41 AM
Received SMS will always be problematic
FULL DISCLOSURE: My company holds two patents on an SMS-based 2FA that eliminates this problem so this is NOT an unbiased or objective opinion.

The real problem here, as it always is with SMS-based 2FA where a message is sent to the user, is excatly that: that the message is sent TO the user.  

Text messages sent to phones are, by definition, both unencrypted and easy to intercept, as Mr. Mitnick has amply demonstrated. The answer to this problem is to reverse the process and have the user authenticate their login or identity by sending a message FROM their phone.  

Here's why this works: the U.S. short code system eliminates spoofing of phone numbers thanks to the carriers.  Cloning/spoofing/duplicating SIMs and IMEIs is a problem for carriers for a simple reason: the lose money when someone doesn't pay for another line.  They solved this problem long ago by implementing a barrier that has yet to be successfully hacked.  

This more secure approach reverses the process by having the user send a text from their device into an independent third-party server.  The server then makes a secure handshake with the web page where the authentication is occurring.  This completely eliminates the type of attack Mr. Mitnick successfully used (man-in-the-middle or man-in-the-browser) and confirms that the inbound SMS has come from the right number, registered IMEI and contains the right code.  I welcome Mr. Mitnick to test the system.  I will be happy to provide him with complete information about it and give him a test account.

Nothing is unhackable (although ours has not yet been successfully hacked) but we are confident that SnapID is substanially LESS hackable than any other SMS-based 2FA method on the market.  


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-41392
PUBLISHED: 2021-09-17
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.
CVE-2020-21547
PUBLISHED: 2021-09-17
Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.
CVE-2020-21548
PUBLISHED: 2021-09-17
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.
CVE-2021-39218
PUBLISHED: 2021-09-17
Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.26.0 and before version 0.30.0 is affected by a memory unsoundness vulnerability. There was an invalid free and out-of-bounds read and write bug when running Wasm that uses `externref`s in Wasmtime. To trigger ...
CVE-2021-41387
PUBLISHED: 2021-09-17
seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid root.