Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le juin 08, 2012, 14:03:07

Titre: [Krebs]Attackers Hit Weak Spots in 2-Factor Authentication
Posté par: igor51 le juin 08, 2012, 14:03:07
Attackers Hit Weak Spots in 2-Factor Authentication

An attack late last week that compromised the personal and business Gmail accounts of Matthew Prince, chief executive of Web content delivery system CloudFlare, revealed a subtle but dangerous security flaw in the 2-factor authentication process used in Google Apps for business customers. Google has since fixed the glitch, but the incident offers a timely reminder that two-factor authentication schemes are only as secure as their weakest component.

In a blog post on Friday, Prince wrote about a complicated attack in which miscreants were able to access a customer's account on CloudFlare and change the customer's DNS records. The attack succeeded, Prince said, in part because the perpetrators exploited a weakness in Google's account recovery process to hijack his CloudFlare.com email address, which runs on Google Apps
Source: Attackers Hit Weak Spots in 2-Factor Authentication (http://feedproxy.google.com/~r/KrebsOnSecurity/~3/jHQqb1evESc/)