Two-factor authentication easily bypassed in proof of concept attack

KnowBe4 chief hacking officer Kevin Mitnick has demonstrated a proof of concept attack that utilizes social engineering and fake domain names to bypass two-factor authentication security, a disturbing turn of events for a commonly used form of security. The attack starts with targeting accounts with a phishing attack, which attempt to trick users into clicking on a website address designed to be similar to a legitimate address – in the PoC, “llnked.com” (that’s with two l’s) as opposed to LinkedIn.com, a misspelling that people may overlook.

Read full news article on SiliconANGLE