top | item 15071989

(no title)

luke3butler | 8 years ago

That's not Authy/Google Authenticator. That's social engineering their way into getting a persons text messages for SMS 2FA.

discuss

order

chatmasta|8 years ago

If you can compromise the iCloud account of an iOS user (pretty sure iOS 2fa is only SMS based), then you can install google authenticator on your own device.

I'm sure it's more complicated than that in reality, but if you have SMS access, you only need to find one weak link in the chain including iCloud/google, email provider, app provider, etc.

15155|8 years ago

> install google authenticator on your own device.

You sure can, but will you then have the requisite TOTP secrets?