|
|
|
|
|
by semi-extrinsic
484 days ago
|
|
Honest question when it comes to 2FA like MS Authenticator: why don't they ask for the 2nd factor first, and password second? Sounds like it would make it much harder to spoof. Currently it's very easy to make a fake MS login prompt, even to customize it with your company name and logo. If you fall for that, they have your PW, which probably at least works without 2FA on some random corpo websites like your time tracking or travel expenses or whatnot. |
|
How? First off if it's a TOTP without a notification the fake website can just ignore the TOTP input and always say it's correct and move to collecting your password. If it's a notification type 2FA, when you go to the fake site it can request a login with your username in the background which will send you a notification, you will enter the 2FA code and then password which the attacker will login with.