RE: Google To Replace SMS Codes With Mobile Prompts in 2-Step-Verification 07-15-2017, 06:41 AM
#2
This doesn't prevent much. Sure It may be a little more secure, but It's not a conclusive security Implementation to prevent unauthorized access of the account.
This Is the vulnerability right here (too easy):
The moment It gets put Into action, Is the best time to SE the account holder. If you have their credentials, the moment you login, Immediately shoot off an SMS (via a virtual number) to the account holder assuming the role of Google's automated service (or a representative) saying something along the lines of "Your account Is almost ready. Please authorize the request and your account will be finalized".
Given It's a new feature, the majority of users are unaware of It's requirements (and exactly how It operates), therefore the SE will have a significant chance of succeeding.
This Is the vulnerability right here (too easy):
Quote:and users can authorize a login request with the tap of a button.
The moment It gets put Into action, Is the best time to SE the account holder. If you have their credentials, the moment you login, Immediately shoot off an SMS (via a virtual number) to the account holder assuming the role of Google's automated service (or a representative) saying something along the lines of "Your account Is almost ready. Please authorize the request and your account will be finalized".
Given It's a new feature, the majority of users are unaware of It's requirements (and exactly how It operates), therefore the SE will have a significant chance of succeeding.














![[+]](https://sinister.li/images/modern/collapse_collapsed.png)