Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But can't the phisher just visit Google and log in there with 2FA, while receiving the 2FA code from the fake site?

This only requires the user not to read the URL and match it to the URL in the Google Authenticator app (as far as I can see right now).



It depends on which 2FA method you use, and there's an associated time window. The TOTP method (Google Authenticator App) of a rotating number must be used within a window of at most a few minutes -- new numbers are generated every 30 seconds, so they could use that if they logged in immediately.

If you use U2F, then the domain name difference will mean that the U2F key can never match unless the attacker has control over DNS and is issued a Google.com SSL certificate by an authority the target's computer trusts.


As acdha said, no, this type of attack isn't possible with U2F.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: