Windows 10: New, very good, Gmail phising atack in the wild

Discus and support New, very good, Gmail phising atack in the wild in AntiVirus, Firewalls and System Security to solve the problem; An effort to get this thread back to the topic: Not using Two-Step Authentication (also known as Two Factor Authentication, TSA, 2FA) to protect... Discussion in 'AntiVirus, Firewalls and System Security' started by AndreTen, Jan 17, 2017.

  1. AndreTen Win User

    New, very good, Gmail phising atack in the wild


    As the word stupid became so popular with you and dencal, seems you are forgetting about fact, that defeating TSA is nothing new. Obviously you won't believe me, would you at least think about it if statement comes from security expert from IBM?

    And again, I'm not saying that TSA isn't better than nothing, but thinking that you are invincible with it... now that would be stupid *Wink
     
    AndreTen, Jan 18, 2017
    #31
  2. DavidY Win User

    My understanding was that Microsoft's own Authenticator app uses the same algorithm as Google Authenticator.
    I only have the Windows Phone 7.5 version (so it's possible this compatibility has been removed now), but my old phone still let me login to my Google account when I tested it just now with the Microsoft Authenticator I have.
     
    DavidY, Jan 19, 2017
    #32
  3. Kari Win User
    I use the S word to stress the fact that not using Two-Step Authentication is just that.

    I have some difficulties to understand your apparent and pointless need to undermine that fact. Somewhat tired to your "yes, but..." I am unsubscribing this thread after posting this; feel free to post next "yes, but..." for other members to read, I will not see it.


    As far as I know you can't get Google verifications to work in latest Microsoft Authenticator app in Windows Phone 8 or Windows 10 Mobile, but in all honesty I have to say I haven't even tried it.
     
  4. DavidY Win User

    New, very good, Gmail phising atack in the wild

    I think the one I use is probably this Authenticator
    For my phone, the Azure authenticator and this app are separate - I understand Microsoft has merged the two into one with the latest app.

    I don't know if this means they've changed the algorithm for non-Azure accounts, but given the Microsoft accounts can also use both the old and presumably the new app, one would imagine it's the same algorithm as before, which would suggest it might work with Google?

    Edit: This suggests the new MS Authenticator should still work with Google, Facebook etc.
    Big Changes Coming to Microsoft Authenticator Apps - Thurrott.com
     
    DavidY, Jan 19, 2017
    #34
  5. simrick Win User
    I think this is a good discussion/topic, and sorry to see Kari has unsubscribed....

    Just thinking out loud:
    If someone were a victim of a MIM (man-in-the-middle) attack, stealing the active cookie session, I think it's then possible to spoof the session, and access an account (even one that's protected with 2FA), at least long enough to do some major damage. I'm not sure exactly how it's done, but it appears to be possible (in my mind).

    Just food for thought... *Smile
     
    simrick, Jan 19, 2017
    #35
  6. dencal Win User
    If its done from an unrecognised computer....it would require phone code authentication.
     
    dencal, Jan 19, 2017
    #36
  7. I did and consequences were severe for me. 2FA is great, in theory, just like relying on AV to detect malware.

    That is exactly why I have posted it, people should know about the risks. I have seen too many people to loose access to their emails, even business, because they have followed the common advise and decided to use it. The only advice I could have offered them was to think twice about using it again. Nothing is perfect.

    It is called 2FA for a reason, you need to provide 2 authentications to access your email, if you lose either, you are damned. If you could gain access with just one, then it would be pointless, it is fairly simple to understand.

    Do you realize, that in many countries, you can get a replaced phone number without providing ID? Not to mention, that faking a phone number to get SMS has been POC way too many times.

    That does not show the important part, since some browsers shows the certificate on the right side.
     
    TairikuOkami, Jan 19, 2017
    #37
  8. AndreTen Win User

    New, very good, Gmail phising atack in the wild

    You didn't check the link I posted in the first post. Here is part of it

    There is also news on ghaks.net
     
    AndreTen, Jan 19, 2017
    #38
  9. That is, what I was looking for, thanks. *Smile
     
    TairikuOkami, Apr 5, 2018
    #39
Thema:

New, very good, Gmail phising atack in the wild

Loading...
  1. New, very good, Gmail phising atack in the wild - Similar Threads - very Gmail phising

  2. Phising E-mail. E-mail was sent to my gmail account regarding my outlook e-mail

    in Windows 10 Gaming
    Phising E-mail. E-mail was sent to my gmail account regarding my outlook e-mail: Just an FYI. I recently signed up for a new account through my child's school, I am using a Mac and I am using Google products at the moment. I do have a separate Microsoft account but I don't use it that often. The following day this e-mail was sent to me claiming it is from...
  3. Phising E-mail. E-mail was sent to my gmail account regarding my outlook e-mail

    in Windows 10 Software and Apps
    Phising E-mail. E-mail was sent to my gmail account regarding my outlook e-mail: Just an FYI. I recently signed up for a new account through my child's school, I am using a Mac and I am using Google products at the moment. I do have a separate Microsoft account but I don't use it that often. The following day this e-mail was sent to me claiming it is from...
  4. Phising E-mail. E-mail was sent to my gmail account regarding my outlook e-mail

    in AntiVirus, Firewalls and System Security
    Phising E-mail. E-mail was sent to my gmail account regarding my outlook e-mail: Just an FYI. I recently signed up for a new account through my child's school, I am using a Mac and I am using Google products at the moment. I do have a separate Microsoft account but I don't use it that often. The following day this e-mail was sent to me claiming it is from...
  5. phising scams how to stop them

    in AntiVirus, Firewalls and System Security
    phising scams how to stop them: I need security help . I have the normal windows 10 security in place yet some of my information has been compromised. I ran the safety scanner it showed infected files and it automatically fixed them. I still don't feel safe. Suggestions Please....
  6. Remove new feature in Gmail

    in Browsers and Email
    Remove new feature in Gmail: Hello,In Gmail a new feature: "Meet New" (Start a meeting)(Join a meeting)How can I remove it ?Answers will be appreciated.Thanks Winver 1903 x64 18362.836 156724
  7. New computers. Why wildly different performance?

    in Windows 10 Ask Insider
    New computers. Why wildly different performance?: I have three Win10 computers that I bought for family use, two laptops and a desktop. They are name brands but basic level since they would only be used for Office and internet. They are all slow to start, slow to close, and slow to open apps right out of the box. I've done...
  8. New gmail features missing?

    in Browsers and Email
    New gmail features missing?: In the old gmail, you could hover over a message sender name, and it would give you the option to select "email', which would group together and display all the messages from that sender. Is there such an option in the new gmail? Also, in the same scenario, how would you...
  9. Good email reader for Gmail

    in Browsers and Email
    Good email reader for Gmail: Does anyone know of a Good email reader for Gmail that will basically sort by sender and then by date for that sender either ascending or descending date. And then also when you delete, it would actually delete the message, it would put it in trash similar to how it works on...
  10. New Flash Player Zero-Day in The Wild

    in Windows 10 News
    New Flash Player Zero-Day in The Wild: A new flaw in latest version of Flash to be patched next week. On my systems I use the free version of Malwarebytes Anti-Exploit to protect my systems. I guess we will see another updated from MS also. https://blog.malwarebytes.org/zero-d..._medium=social Jim *Cool...