So you've created a strong password,adventures in auto-eroticism': economies of traveling masculinity in on the road kept an eye out for sketchy links, and enabled two-factor authentication — what could possibly go wrong?
Well, it turns out the answer is "you."
SEE ALSO: Here's what we know about alleged NSA leaker Reality Leigh WinnerAs the leaked NSA report on Russian efforts to hack the computers of U.S. election officials before the 2016 presidential election demonstrates, we are all often our own biggest security weakness. The document, published by The Intercept, shows that hackers found a way around the protections offered by two-factor authentication that is striking in its simplicity: They asked the targets for their verification codes.
"If the victim had previously enabled two-factor authentication (2FA)," explains a slide detailing the Russian attack, "the actor-controlled website would further prompt the victim to provide their phone number and their legitimate Google verification code that was sent to their phone."
To translate, after tricking victims into entering their email and password into a fake Google site, the hackers found that some victims had 2FA set up on their accounts. This meant that even with the password, hackers were unable to gain access to the Gmail accounts in question — that is, unless they could get the verification codes as well.
So, again, they just straight up asked for them.
"Once the victim supplied this information to the actor-controlled website, it would be relayed to a legitimate Google service, but only after [redacted] actors had successfully obtained the victim's password (and if two-factor, phone number and Google verification code) associated with that specific email account."
Basically, the hackers were able to bypass the email security measures by requesting that the victims give them the keys to the digital castle.
Once access was gained to the accounts, which reportedly belonged to an electronic-voting vendor, the hackers would then email election officials from the hacked accounts and attempt to trick those same officials into opening script-laden Word docs that would compromise their computers.
It's an elaborate bit of spear phishing, and it reminds us that no matter what digital security practices we put in place, we can all still slip up.
In the face of everyday online threats, the best defense (other than setting up 2FA — which you should definitely still do) might be the simplest: exercise caution with every email you receive, and be paranoid as hell.
In the face of skilled Russian hackers? Well, that one's trickier, but maybe start with not handing over your email password, phone number, and 2FA verification code.
Topics Cybersecurity Elections
MoviePass cancels yearly plan, refunds annual subscribersXiaomi's Pocophone F1 is crazy cheap for what it offersDaniel Radcliffe's friendly dead corpse gets the Photoshop treatmentKim Kardashian has proof her waist in Fergie's 'M.I.L.F. $' video is (kind of) real9 terrible festival fashion trends that need to disappear alreadyStop telling women how they should talkNoah Centineo totally improvised one of cutest moments in 'To All The Boys...'Chrissy Teigen crowns the best episode in TV history. Hint: It's from 'The Office.'Londoners fight back against racism with moving message to immigrants8 Snapchat pranks you can pull off from the comfort of your phoneStop telling women how they should talkDC confirms a huge 'Superman' character will appear in its crossover eventWhat to know about the rare, powerful hurricane heading for HawaiiObama hypes Clinton, jabs at Trump in pumped'Chewing Gum' star Michaela Coel speaks out about sexual assaultSony is bringing its robot dog Aibo to the U.S. this fallWhat's coming to Netflix in September 2018Jaguar's classic EEverything coming to Amazon Prime Video in SeptemberObama hypes Clinton, jabs at Trump in pumped Productivity Boost: Enable 'Night Mode' on All Your Devices Argentina vs. Colombia 2025 livestream: Watch World Cup Qualifiers for free Apple's Liquid Glass redesign is dividing the internet Save 45% on the Anker Solix C1000 portable power station Pacers vs. Thunder 2025 livestream: Watch Game 3 of NBA Finals for free Blockchain Explained: How It Works, Who Cares and What Its Future May Hold Portugal vs. France 2025 livestream: Watch U21 Euro 2025 for free What is Vcore and How Does It Help with Overclocking? Today's Hurdle hints and answers for June 10, 2025 What's Thermal Throttling and How to Prevent It Hisense 75 4GHz CPU Battle: AMD 2nd Best TV deal: Buy a Samsung TV and get a Samsung Freestyle Projector for free Poland vs. Georgia 2025 livestream: Watch U21 Euro 2025 for free Analyzing Graphics Card Pricing: October 2018 Best robot vacuum deal: Save 42% on the Eufy E20 3 NYT Strands hints, answers for June 11 I've read hundreds of free Kindle books with Libby. Here's how. Uruguay vs. Venezuela 2025 livestream: Watch World Cup Qualifiers for free 25 Great Games You Can Play on Laptops and Budget PCs
2.9837s , 10195.15625 kb
Copyright © 2025 Powered by 【adventures in auto-eroticism': economies of traveling masculinity in on the road】,Fresh Information Network