Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Stamets [Mirror]@startrek.website to Memes@lemmy.ml · 2 years ago

I will burn your servers to the ground, foul villain

startrek.website

message-square
55
link
fedilink
871

I will burn your servers to the ground, foul villain

startrek.website

Stamets [Mirror]@startrek.website to Memes@lemmy.ml · 2 years ago
message-square
55
link
fedilink
  • Enekk@lemmy.world
    link
    fedilink
    arrow-up
    8
    ·
    edit-2
    2 years ago

    The attack vector is as follows:

    1. Evil.com phishes a user and asks for username and password for Good.com
    2. Evil.com immediately relays those credentials to Good.com
    3. Good.com asks Evil.com for TOTP
    4. Evil.com asks victim for TOTP
    5. Evil.com relays TOTP to Good.com and does a complete account takeover

    The various physical dongles prevent this by using the asking domain as part of the hash. If you activated the dongle on Evil.com, it’ll do nothing on Good.com (except hopefully alerting the SOC at Good.com about a compromised username and password pair).

Memes@lemmy.ml

memes@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !memes@lemmy.ml

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 834 users / day
  • 2K users / week
  • 6.95K users / month
  • 23K users / 6 months
  • 1 local subscriber
  • 50.7K subscribers
  • 12.3K Posts
  • 190K Comments
  • Modlog
  • mods:
  • ghost_laptop@lemmy.ml
  • sexy_peach@feddit.de
  • Cyclohexane@lemmy.ml
  • Arthur Besse@lemmy.ml
  • UI: unknown version
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org