Hacker News new | ask | show | jobs
by dinosaurdynasty 1292 days ago
The token could be made only usable by the cli process that asked for it (should be really).
1 comments

Yes, but that doesn't stop this attack.

1. Attacker runs the cli process to generate the URL

2. Attacker sends the URL to the victim saying "as a second factor verification, you need to copy this code into this form"

3. Victim does it

4. Attacker enters the code into the original cli process