Who would have Hong Kong Archivesthought that, in the end, it would be the humble voicemail that would do us all in?
Your Google, Microsoft, Apple, WhatsApp, and even Signal accounts all have an Achilles' heel — the same one, in fact. And it turns out that if you're not careful, a hacker could use that weakness to take over your online identity.
Or so claims self-described "security geek" Martin Vigo. Speaking to an enthusiastic collection of hackers and security researchers at the annual DEF CON convention in Las Vegas, Vigo explained how he managed to reset passwords for a wide-ranging set of online accounts by taking advantage of the weakest link in the security chain: your voicemail.
SEE ALSO: The hackers just arrived, and they're already breaking VegasYou see, he explained to the crowd, when requesting a password reset on services like WhatsApp, you have the option of requesting that you receive a callwith the reset code. If you happen to miss the phone call, the automated service will leave a message with the code.
But what if it wasn't youtrying to reset your password, but a hacker? And what if that hacker also had access to your voicemail?
Here's the thing: Vigo wrote an automated script that can almost effortlessly bruteforce most voicemail passwords without the phone's owner ever knowing. With that access, you could get an online account's password reset code and, consequently, control of the account itself.
And no, your two-factor authentication won't stop a hacker from resetting your password.
One of Vigo's slides laid out the basic structure of the attack:
1. Bruteforce voicemail system, ideally using backdoor numbers
2. Ensure calls go straight to voicemail (call flooding, OSINT, HLR)
3. Start password reset process using "Call me" feature
4. Listen to the recorded message containing the secret code
5. Profit!
A recorded demo he played on stage showed a variation of this attack on a PayPal account.
"In three, two, one, boom — there it is," Vigo said to audience applause. "We just compromised PayPal."
Vigo was careful to note that he responsibly disclosed the vulnerabilities to the affected companies, but got a less than satisfactory response from many. He plans to post a modified version of his code to Github on Monday.
Notably, he reassures us that he altered the code so that researchers can verify that it works, but also so that script kiddies won't be able to start resetting passwords left and right.
So, now that we know this threat exists, what can we do to protect ourselves? Vigo, thankfully, has a few suggestions.
First and foremost, disable your voicemail. If you can't do that for whatever reason, use the longest possible PIN code that is also random. Next, try not to provide your phone number to online services unless you absolutely have to for 2FA. In general, try to use authenticator apps over SMS-based 2FA.
But, really, the most effective of those options is shutting your voicemail down completely. Which, and let's be honest here, you've likely been looking for a reason to do anyway. You can thank Vigo for providing you with the excuse.
Topics Cybersecurity
Previous:K Street Taxpocalypse
Next:Administering Evil
How to try Sora, OpenAI's AI video generatorBest Nintendo Switch deal: Buy a Nintendo Switch OLED, get a $75 Dell eGift cardFeel the power of a SpaceX Falcon Heavy rocket test in new videoCity halls around the world light up in green after Trump pulls U.S. from Paris Climate AgreementTrump flips the middle finger to the world, your futureTrump says he represents Pittsburgh, not Paris, but, um, well...NYT's The Mini crossword answers for February 16Tim Cook: 'Climate change is real and we all share a responsibility to fight it'Wordle today: The answer and hints for February 17Mike Pence is in denial that literally the entire world disagrees with him on climate changeObama photographer Pete Souza on Trump: 'We failed our children'Wordle today: The answer and hints for February 17Elon Musk to Donald Trump: If you leave the Paris Climate Agreement, I'm outTim Cook: 'Climate change is real and we all share a responsibility to fight it'City halls around the world light up in green after Trump pulls U.S. from Paris Climate AgreementWordle today: The answer and hints for February 17'True Detective: Night Country' finale: What actually happened to Navarro?Mark Zuckerberg says Trump's climate move 'puts our children's future at risk'Here's why flamingos are so incredibly good at standing on one legIn Paris Agreement speech, Trump never acknowledged the reality of global warming The moment Australians learned they'd voted in favor of marriage equality 'Titanic' is returning to cinemas as a remastered version Hey, millennials of London you can still eat sandwiches if you want Russian bots dropped 45,000 garbage tweets on us during the Brexit referendum Why Rian Johnson's Star Wars trilogy should be the ultimate origin story Empire State Building celebrates Australia's same YouTubers from this country are killing it, thanks to the rest of the world EA haters started a campaign to stop parents from buying 'Star Wars Battlefront II' 'Project Hospital' is a modern take on the '90s game 'Theme Hospital' Stove Top created stuffing pants to solve your Thanksgiving struggles Think Facebook is the only company watching you? Think again. Tom Sizemore was thrown off a movie set for allegedly molesting a child Here are the winners of the 2017 National Book Awards YouTuber's advent calendar for tweens was terrible and her excuse was even worse Google Maps' new update makes it easier to find places around you New Google Home feature lets you 'broadcast' messages between devices Your commute just turned into a workout session on this train 'StarCraft' Twitter account fires shots at EA The 'Star Wars: Battlefront II' loot box drama, explained Why heterosexuals are so obsessed with height in online dating
1.7888s , 10130.671875 kb
Copyright © 2025 Powered by 【Hong Kong Archives】,Unobstructed Information Network