Why Nostr? What is Njump?
2024-09-21 15:33:04

Jason Parker (he/they) on Nostr: #Discord told me on #HackerOne that this isn't a security #vulnerability, so cool, ...

#Discord told me on #HackerOne that this isn't a security #vulnerability, so cool, I'll talk about it publicly.

You can disable 2FA¹ on another person's account if you get access to their phone momentarily.

All you have to do is create a new account and put their phone number in as the login; if you verify the code, it strips it from the other account with no warning, and they can't take it back.

So have fun I guess?

¹ SMS is not #2FA

#infosec
Author Public Key
npub1re49l7uznmsuxchckysh23gd7qcrm33qlkzttqulxzwth9jwh7rq0amq7d