Phishing 2FA 25 years ago
twitter.com
twitter.com
A 2FA token is simply another "thing you know". A plugged-in USB dongle is actually "something you have". (Although, technically, it's still "something you know" because it has a secret key; it's considerably more difficult to phish this key.)
Most people are not paying $160 for this, period, when 2FA and passkeys are a "good enough" thing.
Other threat models (malware, physical access) are a different story, of course.
The best was when Gosh took screenshots of the leader of security(whose computer he compromised) berating his reports for lax security, and sent them to all of his reports.
My favorite accounts were “overhead” accounts that lacked ratelimits, was fun to DoS entire rooms of users offline by finding the chat.
to the skillful it was considered basic - for sure. there was a lot of collaborative intelligence in the aol "hacking" scene, though. and you could do a lot on an int. even reading internal aol emails often returned a treasure trove of new tools and information
>The best was when Gosh
legend
>was fun to DoS entire rooms of users offline
yeah that could be done to older computers just by scrolling without rate limits as you mentioned. semi-related - i once found a dos in skype that made use of skype4com.dll to change your display name hundreds of times per second. if you had more memory on your computer than your contacts did you could dos hundreds of people at once. i remember it reminding me of some corny aol "hack"
We've made a lot of progress as new methods and technologies have become available.
* https://en.wikipedia.org/wiki/S/KEY (RFC 1760)