Google Security Vulnerability Allowed Two-Step Verification Bypass
Category: Smartphones
Google has fixed a security hole that permitted attackers to potentially bypass the company's two-step verification feature and take over user accounts.
More Insights
Webcasts
- The Untapped Potential of Mobile Apps for Commercial Customers
- CTO to CTO: Scott Davies, VMware, and Jim Davies, Mitel, Give Voice to the Virtual Desktop
White Papers
- Understanding Holistic Database Security 8 Steps to Successfully Securing Enterprise Data Sources
- Holistic Risk Management: Perspectives from IT Professionals
Reports
More >>According to Duo Security, the vulnerability rested in the way application-specific passwords (ASPs) were used for applications that do not support logins using two-step verification. Designed with an eye towards improving account security, two-step verification provides users with a special code via text message or phone call when they attempt to log on to their Google account. The user will then have to enter that code as well in order to log in.
... Read full story on Dark Reading


