Who would have Family Movies | Adult Movies Onlinethought that, in the end, it would be the humble voicemail that would do us all in?
Your Google, Microsoft, Apple, WhatsApp, and even Signal accounts all have an Achilles' heel — the same one, in fact. And it turns out that if you're not careful, a hacker could use that weakness to take over your online identity.
Or so claims self-described "security geek" Martin Vigo. Speaking to an enthusiastic collection of hackers and security researchers at the annual DEF CON convention in Las Vegas, Vigo explained how he managed to reset passwords for a wide-ranging set of online accounts by taking advantage of the weakest link in the security chain: your voicemail.
SEE ALSO: The hackers just arrived, and they're already breaking VegasYou see, he explained to the crowd, when requesting a password reset on services like WhatsApp, you have the option of requesting that you receive a callwith the reset code. If you happen to miss the phone call, the automated service will leave a message with the code.
But what if it wasn't youtrying to reset your password, but a hacker? And what if that hacker also had access to your voicemail?
Here's the thing: Vigo wrote an automated script that can almost effortlessly bruteforce most voicemail passwords without the phone's owner ever knowing. With that access, you could get an online account's password reset code and, consequently, control of the account itself.
And no, your two-factor authentication won't stop a hacker from resetting your password.
One of Vigo's slides laid out the basic structure of the attack:
1. Bruteforce voicemail system, ideally using backdoor numbers
2. Ensure calls go straight to voicemail (call flooding, OSINT, HLR)
3. Start password reset process using "Call me" feature
4. Listen to the recorded message containing the secret code
5. Profit!
A recorded demo he played on stage showed a variation of this attack on a PayPal account.
"In three, two, one, boom — there it is," Vigo said to audience applause. "We just compromised PayPal."
Vigo was careful to note that he responsibly disclosed the vulnerabilities to the affected companies, but got a less than satisfactory response from many. He plans to post a modified version of his code to Github on Monday.
Notably, he reassures us that he altered the code so that researchers can verify that it works, but also so that script kiddies won't be able to start resetting passwords left and right.
So, now that we know this threat exists, what can we do to protect ourselves? Vigo, thankfully, has a few suggestions.
First and foremost, disable your voicemail. If you can't do that for whatever reason, use the longest possible PIN code that is also random. Next, try not to provide your phone number to online services unless you absolutely have to for 2FA. In general, try to use authenticator apps over SMS-based 2FA.
But, really, the most effective of those options is shutting your voicemail down completely. Which, and let's be honest here, you've likely been looking for a reason to do anyway. You can thank Vigo for providing you with the excuse.
Topics Cybersecurity
10 Tech Products That Are Next to Impossible to RepairDo You Desire Pizza, or Does Pizza Desire You?Losing: A Memory of the Richest Kid at Boarding SchoolPhotographs of Lost Gloves: A Thriving SubcultureBefore Fiction Dealt with FeelingsRose Gold: Sara Cwynar on Consumers and DesireJim Harrison: A Remembrance by Terry McDonellFun with Textiles: Samantha Bittman’s Woven PaintingsThe Lingering Anxieties of Growing Up UndocumentedFive Limericks (in the Style of Edward Lear)When Drummers Become Writers: The Strange Wisdom of Method BooksYou, Too, Can Be T. S. Eliot’s Child. Just Give It a Try.In “Denis the Pirate,” Denis Johnson Goes for SwashbucklingDo You Desire Pizza, or Does Pizza Desire You?Rose Gold: Sara Cwynar on Consumers and DesireTo Hölderlin (from Rilke with Love)A Memoir of Life at a Moving CompanyHow Fonograf Editions Is Bringing Poetry Back to VinylThe Art of Deodorant DesignRemembering Jean Stein, 1934–2017 4 reportedly arrested after 'Game of Thrones' episode leaked in India Deadmau5 interrupts his wedding weekend to buy 'Rick and Morty' Szechuan sauce Crotch charms to add to your bikini are surely a recipe for disaster Detail in 'Game of Thrones' Episode 6 trailer hints at a chilling White Walker reveal Uber is releasing a new tipping feature in the UK, and critics are not happy about it 'League of Legends' pro blames bad performance on ... something sexual Scientists find 91 volcanoes slumbering below Antarctic Ice Sheet Usain Bolt's final race ended with an unexpected injury, but he's still a legend Gilly's nighttime reading on 'Game of Thrones' may have just changed everything Fan strikes 'Rick and Morty' gold The only 'Game of Thrones' ship worth shipping is still afloat The top 10 companies for diversity in tech, ranked by their own underrepresented employees Multiplayer in 'No Man's Sky' gets fans' hopes up all over again Samantha Bee interviews former neo The next Apple Watch could be the first must Uber's Travis Kalanick 'disappointed' that his awful past caught up with him 'Game of Thrones' fans are all making the same joke about the White Walkers 'Game of Thrones' brought back someone we've sorely missed, and we're screaming Festival bans pineapples because life is unfair Anna Paquin spots her own 'True Blood' sex scene in the background of BBC News
2.3628s , 10131.765625 kb
Copyright © 2025 Powered by 【Family Movies | Adult Movies Online】,Defense Information Network