ZeroHour
Schneier on Securitypublished ()ingested

New Technique to Hijack Social Media Accounts

mediumPhishing & fraudimportance 30
Full article167 words · extracted from schneier.com · click to collapse

Access Now has documented it being used against a Twitter user, but it also works against other social media accounts:

With the Doubleswitch attack, a hijacker takes control of a victim’s account through one of several attack vectors. People who have not enabled an app-based form of multifactor authentication for their accounts are especially vulnerable. For instance, an attacker could trick you into revealing your password through phishing. If you don’t have multifactor authentication, you lack a secondary line of defense. Once in control, the hijacker can then send messages and also subtly change your account information, including your username. The original username for your account is now available, allowing the hijacker to register for an account using that original username, while providing different login credentials.

Three news stories.

Tags: fake news, hacking, impersonation, phishing, social media, Twitter, two-factor authentication

Posted on June 19, 2017 at 6:44 AM23 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2017/06/new_technique_t.html