Ethereum.org Forums Database Compromised
blog.ethereum.org
blog.ethereum.org
Haha in complete contrast to what Yahoo prob would have done. (Given that Yahoo is a much larger company with more legal and bureaucracy so they may be unable to do this. but still, 3 yrs???)
Forgive me if I'm missing something blatantly obvious, but how was a hacker able to gain backup access with just a phone number? What kind of auth is that?
If a: 2-Factor Authentication with Short Message Service (called "text" in the US).
If b: It's how Google's 2FA works by default, falls back to SMS.
Basically, getting control of (i.e. stealing) the 2nd factor in the 2FA scheme, and bypassing the 1st factor, the password (by resetting it). Plausible.
1. attempt to log in to target's email system
2. "I forgot my password"
3. get 2FA key via SMS
4. enter 2FA key and new password, gain access to email
<rummage through email looking for anything interesting>
5. attempt to log in to target's backup system
6. "I forgot my password"
7. get password reset key via email...