DidYouKnowGaming? Youtube Channel Hacked by "Ripple"

Maximumbeans

3DS is love, 3DS is life
Member
Joined
Jun 7, 2022
Messages
697
Trophies
0
Location
England
XP
1,570
Country
United Kingdom
Someone more infosec savvy than me will probably know: how is this happening despite things like 2FA? Isn't 2FA basically unbreakable as long as you control who has the necessary info?
 

SylverReZ

Dat one with the Rez
Member
GBAtemp Patron
Joined
Sep 13, 2022
Messages
7,129
Trophies
3
Location
The Wired
Website
m4x1mumrez87.neocities.org
XP
21,879
Country
United Kingdom

jakl_53

Well-Known Member
Newcomer
Joined
Dec 27, 2009
Messages
52
Trophies
1
XP
60
Country
United States
Someone more infosec savvy than me will probably know: how is this happening despite things like 2FA? Isn't 2FA basically unbreakable as long as you control who has the necessary info?
Other people have responded to this much better than I can. Also some of the affected channels posted videos on what happened. 2FA is only security for logging in initially. What these turds are doing are using malware to highjack a session token. Session tokens allow your device to stay logged in for a period of time. Especially when you do more than stay on one page. Such as logging into youtube and clicking on a couple of videos. Every time you click on a video you are going to a different web page. Without session tokens you would have to log in every time you click on a different page within one website. They basically steal that and now the website thinks that the attacker is legitimately logged in and they really are.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    SylverReZ @ SylverReZ: @Psionic Roshambo, Thats pretty cool.