Saw a video of a youtuber that got his account overtaken which has 2fa enabled (not sure which method but I’m thinking sms). He says he didn’t get phished, downloaded anything and his session cookies weren’t stolen and I believe him. The only clue is that he received a sms otp from google but was invalid when he inputted it which let’s me to believe he relied on SMS for 2fa in the first place. My theory is he reused passwords and his number was overtaken but I’m not sure if that’s the case since he did receive the google otp so that leaves out the common phone rep social engineering methods of porting out and fowarding. What else could it be? My paranoia is kinda acting up

Tldr: A YouTuber’s account was hacked despite having 2FA. While unsure of the exact method, potential factors include relying on SMS OTP and the possibility of password reuse. No session cookies were stolen, nothing downloaded and no links clicked

Edit for timestamp: its kinda difficult since he jumps around a lot but he begins to talk about it around the 2min 30sec mark and stops at around the 6min mark

  • Extras@lemmy.todayOP
    link
    fedilink
    arrow-up
    5
    ·
    10 months ago

    He did talk about session cookies/tokens in the video which is a possibility but I’m under the impression that this is not what happened since he was already aware of that possibility and didn’t do anything to facilitate that.

    • NoneYa@lemm.ee
      cake
      link
      fedilink
      arrow-up
      7
      ·
      10 months ago

      Nothing he’s aware of. I haven’t watched the video, but there’s no way to know for sure that you didn’t do any of that because all it takes is one hit.

      Additionally, with exploits like mouse jacking, it’s entirely possible for someone to do things on your computer without your knowledge, even remotely.

    • candyman337@sh.itjust.works
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      10 months ago

      I believe there is another method where you can intercept an SMS text somehow. I read about it a while back so I don’t know the specifics, but I know that since SMS is unsecure there is a way to grab the data while it’s being sent to you