sigh - another nick in 2FA's armor.
an attacker can craft an email which will send you to a phishing server. This server will make you think you're entering your credentials and 2FA code, but in reality you're just entering it to the attacker.
listen, 2FA is still a good idea, but you need to make sure that you're actually going to the site you think you are. Check the link in emails, type it in manually.
This attack *doesn't* work on fob-based 2FA.
@0x56 The old rule "don't click links in emails" is really limiting, really annoying, but it sure stops a lot of problems (like this one) cold.
It's probably also just slightly too complicated for average users to remember, understand, or follow consistently.
Sigh indeed.
@0x56 you folks always remind me not to get to lax when it comes to security.
Thanks for that and for all the info too.