Hacker News new | ask | show | jobs
by jonknee 4790 days ago
Why not? If you think you're logging in you'll also need to enter the 2FA code and if you do that the attacker can get an active session.
1 comments

The attacker (most likely) wouldn't know the phone number, so the user would have to recognize that the text prompt isn't displaying the last 4 digits of their phone number like it usually does. Then again, if you're already oblivious to the fact you're not on an official google login form, it's completely possible to miss that as well.