PoisonSeed Hackers Bypass FIDO Keys Using QR Phishing and Cross-Device Sign-In Abuse (thehackernews.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 21 Jul 14:25
https://sh.itjust.works/post/42541958

#cybersecurity

threaded - newest

vk6flab@lemmy.radio on 21 Jul 14:38 collapse

This appears to be leveraging the complexity associated with setting up MFA using QR codes which to the uninitiated is sheer magic.

It’s unclear why a user who understands the process would ever scan a QR code using their authenticator application during the process of signing in anywhere.

It’s entirely possible that I don’t understand the article, in which case, can someone please enlighten me?