TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

DontDuo: Bypass 2FA with DTMF Tones

54 点作者 _wldu超过 5 年前

9 条评论

floatingatoll超过 5 年前
To explain what&#x27;s going on here for the unaware —<p>1) Duo is a commercial service that offers multi-factor authentication through a variety of means, one of which is the Phone Call.<p>2) This site lets you register them as your Duo phone number, when demanded to do so by someone who&#x27;s trying to protect your high-value access from being hijacked (such as your employer).<p>3) This site provides you a phone number that auto-accepts all Duo authentication requests, even if you&#x27;re asleep, offline, or otherwise not authorizing the hacking activity.<p>4) This site has zero contact information and accountability, and could very well be backed by a black market site that offers hackers lookup access for any Duo phone number for $50&#x2F;number.<p>NOTE: I, personally, would absolutely push to fire anyone I found using this, no matter where I worked.
评论 #20936742 未加载
评论 #20936738 未加载
评论 #20941259 未加载
markstos超过 5 年前
Or instead of handing over your second factor authentication to a startup web service, you could buy a Yubikey, leave it on your keyring or plugged into your laptop and just touch it.<p>Some Yubikey models also store the secrets that generate the frustrating 6 character TOTP codes. A pairing a Yubikey with a desktop app, you can copy&#x2F;paste the codes instead of the error-prone process of manually re-typing them.
评论 #20936153 未加载
warhorse10_9超过 5 年前
This is a horrible idea. I just can&#x27;t. Why does this service even exist. I seriously hope duo figures out the numbers this site is using and blacklists them.
评论 #20936002 未加载
评论 #20936040 未加载
评论 #20942856 未加载
评论 #20936120 未加载
评论 #20936053 未加载
snek超过 5 年前
Remove your account defenses while simultaneously giving authentication information to a third party? What could go wrong‽
morpheuskafka超过 5 年前
If you fill this out with the same email as the protected account, you&#x27;re basically inviting an untrusted third party to launch a brute-force attack on your now-defenseless account.<p>Using this sounds like a good way to take liability when your account gets hacked. It will not look good to be fired for intentionally defeating corporate security systems.
goode超过 5 年前
Duo was one of the last things keeping me from switching to Google-free AOSP, and I toyed with a similar idea while trying to reverse-engineer a free software replacement. Instead, I ended up writing a small tool that allows you to use any old HOTP authenticator with Duo. I use FreeOTP+ on my phone, but you could just as easily stick that HOTP secret in a script or onto a Yubikey. You might find it useful if you&#x27;re working your way up to 100% Stallman status: <a href="https:&#x2F;&#x2F;github.com&#x2F;evan-goode&#x2F;duolibre" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;evan-goode&#x2F;duolibre</a>.<p>By the way, I gotta say this project is pretty hilarious, and you&#x27;re a true baller for trying to sell this to people.
keyle超过 5 年前
The website is strangely sparse. Just trust us. We&#x27;re a website, we have https. All I could work out is that they&#x27;re apparently from Georgia according to their generated T&amp;C.
DKnoll超过 5 年前
I got the trial. Gave me a 201 area code number. Called it and it waited some seconds after answering, played a DTMF tone and hung up. No, I didn&#x27;t test it with Duo (lol). Every time this number receives a phone call it increments a login counter on the dashboard.
评论 #20936575 未加载
ars超过 5 年前
I&#x27;m very confused about what this is.<p>Duo as in Google&#x27;s Duo video calling? There&#x27;s 2FA on that? I&#x27;ve never seen any.<p>Or is there some other Duo it&#x27;s referring to?
评论 #20936061 未加载