国产成人 综合 亚洲欧美,羞羞影院成人午夜爽爽在线,中文字幕av在线一二三区,午夜私人成年影院在线观看,男人把大ji巴放进女人视频

okx

Hackers reveal security flaw that led to unauthori

時間:2024-03-02|瀏覽:278

Summary:

?A security researcher recently revealed that a large database containing company two-step verification codes was publicly exposed.

?The data relates to a service used by Google, Meta and TikTok to send text messages containing verification codes to verify a user's identity as quickly as possible. .

?These two-factor authentications present many forms of crime, from hacking into a person's iCloud to stealing their phone number to bypassing encryption.

HACKERSREVEALSECURITYFLAWTHATLEDTOUNAUTHORIZEDACCESSTOTWOFACTORAUTHENTICATIONCODES

A security researcher has discovered an unprotected database that managed access to the services of some of the world's largest tech companies. The database belongs to a short message service (SMS) routing operator responsible for sending two-factor authentication (2FA) codes to users of Meta, Google and possibly crypto companies.

Researcher Anurag Sen discovered that the company's YX International database was not password protected on the public Internet. Anyone who knows the public Internet Protocol (IP) address can view the data.

Users affected by two-factor authentication breach

YX International sends security codes to users who log into the Meta, Google and TikTok platforms. The company ensures that users' messages are delivered quickly through global mobile networks. The messages it sends include security codes that form part of the two-factor authentication schemes used by many large companies to protect user accounts.

Some service providers, such as Google, can verify the user's authenticity by sending an SMS code after entering a password. Other authentication options include generating a string of codes from the authentication application to supplement the password.

HACKERSREVEALSECURITYFLAWTHATLEDTOUNAUTHORIZEDACCESSTOTWOFACTORAUTHENTICATIONCODES
The red box shows weaknesses in SMS 2FA authentication | Source: All Things Auth

While two-factor authentication is designed to improve security, it's not a magic bullet. As a result, crypto exchange Coinbase warns that 2FA is a minimum security measure, but not absolutely secure. Hackers may still find a way to steal funds from crypto wallets.

Coinbase stated:

"While 2FA is designed to increase security, it is not foolproof. Hackers who obtain two-factor authentication can still gain unauthorized access to accounts. Common methods include phishing attacks, account recovery procedures, and malware. Hackers It is also possible to intercept text messages used in 2FA."

Criminals are using these methods to bypass 2FA

Last year, reports emerged about how criminals were bypassing 2FA on Apple devices. Hackers can access Apple's cloud platform iCloud and replace a user's phone number with their own. This scheme compromises funds held in crypto wallet apps on Apple devices, as some apps may send verification codes to compromised phone numbers.

Criminals can also use SIM swapping to conduct two-step verification crypto scams. In this attack method, criminals convince mobile carriers such as AT&T or Verizon to transfer phone numbers from the rightful owner to the fraudster's name. The criminal then only needs one more piece of information to gain access to the self-hosted wallet app that actually has the phone number.

In light of the surge in quantum technology, Apple recently improved the security of its Secure Enclave hardware device embedded in iPhones. Post-quantum encryption schemes create new keys every time a malicious actor compromises an old key.

This feature can help crypto wallet developers improve their customers’ crypto security by storing critical information in Secure Enclave. So far, at least one provider has used Secure Enclave to grant access to its wallet app.

Reporters contacted Binance and Coinbase, the world’s largest cryptocurrency exchanges, to find out whether the XY International data breach affected their users. Neither company responded by the time of publication.#安全漏洞 #2FA

熱點: LED TO TWO

歐易

歐易(OKX)

用戶喜愛的交易所

幣安

幣安(Binance)

已有賬號登陸后會彈出下載

« 上一條| 下一條 »
區(qū)塊鏈交流群
數(shù)藏交流群

合作伙伴

裝修裝飾網(wǎng) 媽媽知道 談股票 借春秋財經(jīng) 幣圈交流群 非小號行情 減肥瘦身吧 聚幣網(wǎng) 谷歌留痕 周公解夢 百悅米 去玩唄SPA 兼職信息網(wǎng) 幣圈論壇 玩票票財經(jīng) 百科書庫 天天財富 皮卡丘資訊 金色幣圈 美白沒斑啦 培訓(xùn)資訊網(wǎng) 幣圈官網(wǎng) 秒懂域名 數(shù)字黃金 借春秋 數(shù)字財經(jīng) 今日黃金 愛網(wǎng)站 元宇宙Web 幣圈ICO官網(wǎng) 旅游資訊網(wǎng) 寶寶起名 黃金行情 趣玩幣 代特幣圈 茶百科 玩合約
非小號交易所排名-專業(yè)的交易行情資訊門戶網(wǎng)站,提供區(qū)塊鏈比特幣行情查詢、比特幣價格、比特幣錢包、比特幣智能合約、比特幣量化交易策略分析,狗狗幣以太坊以太幣玩客幣雷達幣波場環(huán)保幣柚子幣萊特幣瑞波幣公信寶等虛擬加密電子數(shù)字貨幣價格查詢匯率換算,幣看比特兒火幣網(wǎng)幣安網(wǎng)歐易虎符抹茶XMEX合約交易所APP,比特幣挖礦金色財經(jīng)巴比特范非小號資訊平臺。
非小號行情 yonghaoka.cn 飛鳥用好卡 ?2020-2024版權(quán)所有 桂ICP備18005582號-1