Websites with fake MFA: security theater?

https://news.ycombinator.com/item?id=36726414
by NoZebra120vClip • 3 years ago
23 18 3 years ago

Greetings, I may have discovered a very common weakness in multi-factor authentication (MFA) as widely implemented by many websites and organizations.

So far, the suspects include GitLab and Credly: the exploit begins by invoking the "Forgot My Password" flow, then procuring the "Reset Password" email. Follow the link found in that email message, provide a new password, and you're signed in to the victim's account without ever being challenged for 2FA.

Now, the challenge here is intercepting that email message, but that's a trivial feat: it's in plaintext and you probably know where it was sent. You may need to execute a takeover of the email account. But this may be easier than procuring the victim's TOTP secret, or otherwise providing that second factor, and you also don't need to know the other factor -- the password!

Let's call it 0FA.

I contacted GitLab via their HackerOne bug bounty program, and the application was rejected, because an email intercept is not part of their account threat model.

I innocently contacted Credly Support, asking where to find recovery codes, and Dominique informed me with a straight face how to completely bypass MANDATORY TOTP MFA and recover my account WITHOUT EVEN GIVING THE PASSWORD to sign in. And then, she explained, I would be free to disable MFA or do whatever I wanted! yay

So am I wrong? Is this a nothingburger, or is it really what it appears to be: security theater, brought to us by techbros who don't know how to roll their own auth?

Related Stories

Loading related stories...

Source preview

news.ycombinator.com