Researchers at Duo Security detailed an attack that could have allowed a hacker to hijack a user's Google account
Google has fixed a security hole that permitted attackers to potentially bypass the company's two-step verification feature and take over user accounts.
According to Duo Security, the vulnerability rested in the way application-specific passwords (ASPs) were used for applications that do not support logins using two-step verification. Designed with an eye towards improving account security, two-step verification provides users with a special code via text message or phone call when they attempt to log on to their Google account. The user will then have to enter that code as well in order to log in.
About the Author(s)
You May Also Like
The CISOs Guide to the Software Supply Chain
March 21, 2024How CISOs Navigate Uncertainty: A Fireside Chat
March 26, 2024Stop living on the edge. Switch to the Branch of the Future
March 27, 2024