View Single Post
Old 07-25-2018, 06:24 AM  
Arnox
Confirmed User
 
Arnox's Avatar
 
Industry Role:
Join Date: Sep 2009
Location: Radelaide
Posts: 2,167
Quote:
Originally Posted by KlenTelaris View Post
By riding on session. And here is how it works: let's say i have trojan on your PC, and i have access to your browser cookies. So, you login into system, using the 2FA device, and then i copy your cookie into my browser,and i get instant access. This works only as long cookie is valid, so if you click logout it wont work anymore, but if you leave browser without deleting cookie, it will be compromised.
Yeah, that's a whole new level of compromised. It'd be nice if they did what crypto exchanges do with Google Auth: every transaction you need to use your 2FA. Logging in 2FA simply isn't enough.
__________________
Need Text? X Copywriters | Adult Writing Service - [email protected]
Arnox is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote