作为一种安全措施,双因素身份验证越来越受欢迎。例如,谷歌、Facebook、Twitter和其他许多服务如今都有两步安全选项,还有许多银行和信用社。
我想知道是否使用谷歌语音电话号码作为所谓的物理设备,人们将接收短信代码,以确认一个人拥有物理设备是错误的,因为你的GV帐户可能会被黑客攻击,然后你的物理设备实际上被偷了?
如果您使用的是双因素Google身份验证,它将一个应用程序放在您的智能手机上以确认身份,如果您认为Google是安全的,那么使用GV对其他人是否安全呢?
发布于 2018-02-16 17:11:46
让我们介绍一些可能的2因素选项和可能的攻击形式:
- Via social engineering attack they can attempt a SIM-swap but they will need your password to access any sites
- Malware on your 2FA device or accessing device.- If they steal ANY OTHER device that has google voice installed, bypass any password protection (on Linux, Windows, Mac this often possible) AND they have your password or it is a trusted device with a service, they could possibly gain full access to accounts.
- Malware on your 2FA device or accessing device.
- If they hit the 'reset password link' on a site:
- If they have phished for your email password and you DONT have 2fa on your email AND you have GV and email on the same account (or the same pass on two different google accounts), then Alan is exactly correct that this is essentially not 2fa. If you DO have 2fa on your email, then it is still 2fa. They can phish for your google password, and when they have it they can go to any website and select 'forgot password', but it won't help because they don't have the second 'thing you have', namely a SEPARATE (see below) GV account for 2fa. The gmail pass doesn't help them get into the site. But you DONT want GV on the same gmail account that your 2fa is on anyways (see below), so usually this WILL be 2fa as long as you have different passwords on each account.- (YOU CAN LOCK YOURSELF OUT: DO NOT USE THE SAME GOOGLE ACCOUNT FOR BOTH GOOGLE VOICE TO RECEIVE 2FA AND THE ACCOUNT THAT SENDS OUT THE 2FA)- If they steal any other device that has a push service installed- Malware on your 2FA device or accessing device.总之,GV是否是一个“大错误”取决于你想要承担的风险水平。推送或代码生成可能是最安全的,但它们都有自己的攻击向量。恶意软件是非常不可能的,但也不是不可能的(除了推送之外,所有这些软件都是脆弱的)。您的设备被盗和一个有动机的攻击者试图劫持您的帐户也是非常不可能的,但有可能。但是所有的方法都很容易被偷。GV增加了额外的风险,因为现在任何被偷的GV设备都很容易受到攻击。但是GV确实增加了额外的方便:你可以推到多个设备,你不必去拿你的手机,你可以看到它弹出在你的笔记本电脑上,然后输入它。值得冒额外的险吗?(可能有2%的机会让你的设备在一年内被偷(对任何方法都是这样,但更糟的是GV,因为你有其他设备可以被偷),还有5%的可能性,攻击者有足够的动机劫持你的帐户。所以这是你的绝对风险,值得吗?那随你的便。
但是,如果你真的和GV一起去的话,下面的建议是:
(想出其他攻击矢量吗?有什么修正吗?让我知道,我会把它加到列表中。)
发布于 2013-03-22 17:50:27
这方面的主要问题是,当有人在您的计算机上有恶意软件(如键盘记录器),他们将能够获得您的谷歌语音密码以及您的正常帐户密码。然后,他们可以通过这两个因素的认证。如果你总是从一个单独的系统访问谷歌语音,技术上来说,你仍然是两个因素。
发布于 2013-06-01 09:02:28
如果您限制访问您的谷歌帐户,并实施多因素认证,以访问之前访问谷歌语音,这将增加未经授权访问的门槛,并将更安全地使用。但是,通常用户也不会在物理设备上使用PIN或其他任何东西,当然,您也不能在物理上丢失它。
如果你的电话号码被泄露了,你也可以很容易地用谷歌语音改变它。
https://security.stackexchange.com/questions/33068
复制相似问题