Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


A Security Issue filter_list
Author
Message
A Security Issue #1
I have recently figured out a flaw that can be used to hack into certain profiles given that the hacker has access to the user's phone and email or in certain cases just the email. Almost all the big social media and messaging platforms have implemented login authentication using authentication apps (Google Authenticator, Authy, etc.). The problem is that after setting up a profile with one of those apps if you accidentally delete the app you will lose access to all your profiles. I faced the exact same thing a few days back (used Google Authenticator). After that, I was able to access to facebook by sending code to my phone but failed to get into my Reddit and Discord accounts as my number was not set up there. Unfortunately I lost my Discord completely as the support stuff said they can't recover such account. Even I was not able to recover my data. But in case of Reddit they were able to remove the authentication from my account. The thing is, when you set up the thing a back up key is provided and I didn't care to save them and had to pay the cost. So, to many this can be a hassle and thus they will keep using accounts without any authentication measures which as a result make them vulnerable to attacks.
Quote:Logic is POWER, Knowledge is an asset.

Reply

RE: A Security Issue #2
So to sum all that up; you are just trying to say that since its a hassle to lose all your accounts over 2FA, some people may not use it and they are vulnerable?
Great one.
(This post was last modified: 04-01-2020, 04:27 AM by Crimin4L.)
[Image: signature.png]

[+] 2 users Like Crimin4L's post
Reply

RE: A Security Issue #3
Quote:But in case of Reddit they were able to remove the authentication from my account.
What sort of credentials did they request, to verify that you're the rightful owner of the account?
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: A Security Issue #4
(04-01-2020, 04:27 AM)mothered Wrote:
Quote:But in case of Reddit they were able to remove the authentication from my account.
What sort of credentials did they request, to verify that you're the rightful owner of the account?

They requested just the username, nothing else. I sent my username via the email that is linked to my Reddit account. That was enough for them to verify my ownership.
Quote:Logic is POWER, Knowledge is an asset.

Reply

RE: A Security Issue #5
(04-01-2020, 05:53 AM)ethics404 Wrote:
(04-01-2020, 04:27 AM)mothered Wrote:
Quote:But in case of Reddit they were able to remove the authentication from my account.
What sort of credentials did they request, to verify that you're the rightful owner of the account?

They requested just the username, nothing else. I sent my username via the email that is linked to my Reddit account.  That was enough for them to verify my ownership.
I'd say they've predominantly used your email account to verify ownership, which Is appalling from a security standpoint.

Anyone (myself Inclusive), can spoof your email address, easily grab your username and have the authentication removed.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: A Security Issue #6
(04-01-2020, 06:08 AM)mothered Wrote:
(04-01-2020, 05:53 AM)ethics404 Wrote:
(04-01-2020, 04:27 AM)mothered Wrote: What sort of credentials did they request, to verify that you're the rightful owner of the account?

They requested just the username, nothing else. I sent my username via the email that is linked to my Reddit account.  That was enough for them to verify my ownership.
I'd say they've predominantly used your email account to verify ownership, which Is appalling from a security standpoint.

Anyone (myself Inclusive), can spoof your email address, easily grab your username and have the authentication removed.

Exactly. That shows how easy it is to compromise such accounts.
Quote:Logic is POWER, Knowledge is an asset.

Reply

RE: A Security Issue #7
(04-01-2020, 06:19 AM)ethics404 Wrote:
(04-01-2020, 06:08 AM)mothered Wrote:
(04-01-2020, 05:53 AM)ethics404 Wrote: They requested just the username, nothing else. I sent my username via the email that is linked to my Reddit account.  That was enough for them to verify my ownership.
I'd say they've predominantly used your email account to verify ownership, which Is appalling from a security standpoint.

Anyone (myself Inclusive), can spoof your email address, easily grab your username and have the authentication removed.

Exactly. That shows how easy it is to compromise such accounts.
Hence the objective of this thread.

They (Reddit), should have other measures In place to verify account ownership, such as a security questionnaire. It can Include things like when the account was created, the (approximate) last login time & date and so forth.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply

RE: A Security Issue #8
Authy does have backups. That's 2FA, acting as designed. Some companies will offer to remove 2FA if you provide ID and whatnot.
[Image: 7ajmN5P.jpg]

Telegram: Oni_SL (Link)

[+] 1 user Likes Oni's post
Reply

RE: A Security Issue #9
(04-01-2020, 06:31 AM)mothered Wrote:
(04-01-2020, 06:19 AM)ethics404 Wrote:
(04-01-2020, 06:08 AM)mothered Wrote: I'd say they've predominantly used your email account to verify ownership, which Is appalling from a security standpoint.

Anyone (myself Inclusive), can spoof your email address, easily grab your username and have the authentication removed.

Exactly. That shows how easy it is to compromise such accounts.
Hence the objective of this thread.

They (Reddit), should have other measures In place to verify account ownership, such as a security questionnaire. It can Include things like when the account was created, the (approximate) last login time & date and so forth.

Absolutely. But the reality is those companies want to offer a convenient and user-friendly experience which is done at the cost of security. Many real owners forget such credentials you mentioned above and end up creating new accounts to eschew the hassle. Many even don't bother to contact the support stuffs or even don't know about it. Recently some app introduced magic link to login which is sent to respective account's email. A very convenient way to login but you know the problem behind it!
Quote:Logic is POWER, Knowledge is an asset.

Reply

RE: A Security Issue #10
(04-01-2020, 07:13 AM)ethics404 Wrote: But the reality is those companies want to offer a convenient and user-friendly experience which is done at the cost of security.
Agree.

I've been In the cyber security sector for decades, and have circumvented the security of countless entities on both a corporate and personal level- all without malicious Intent. "Every" Industry, even Fortune 500 companies, have at least one vulnerability that can be exploited using a combination of technical and/or social engineering attack vectors.

In the case of Reddit, I'm not suggesting to Implement Fort Knox-type measures, but rather a few simple, yet very effective procedures that will significantly help keep accounts secure. As It stands, It's a "key under the mat" type security- an open Invitation (so to speak) for anyone to compromise a given account.

(04-01-2020, 07:13 AM)ethics404 Wrote: Many real owners forget such credentials you mentioned above
Security travels both ways- company > client & client > company.

If the company made It a prerequisite to remember (or keep a secure copy, locally) of certain credentials when creating the account for the purpose of a recovery questionnaire, then the account holder will be well-prepared to fulfill their request.
[Image: AD83g1A.png]

[+] 1 user Likes mothered's post
Reply