Who would have The Naughty New Mom Is My First Love Teacher (2025)thought that, in the end, it would be the humble voicemail that would do us all in?
Your Google, Microsoft, Apple, WhatsApp, and even Signal accounts all have an Achilles' heel — the same one, in fact. And it turns out that if you're not careful, a hacker could use that weakness to take over your online identity.
Or so claims self-described "security geek" Martin Vigo. Speaking to an enthusiastic collection of hackers and security researchers at the annual DEF CON convention in Las Vegas, Vigo explained how he managed to reset passwords for a wide-ranging set of online accounts by taking advantage of the weakest link in the security chain: your voicemail.
SEE ALSO: The hackers just arrived, and they're already breaking VegasYou see, he explained to the crowd, when requesting a password reset on services like WhatsApp, you have the option of requesting that you receive a callwith the reset code. If you happen to miss the phone call, the automated service will leave a message with the code.
But what if it wasn't youtrying to reset your password, but a hacker? And what if that hacker also had access to your voicemail?
Here's the thing: Vigo wrote an automated script that can almost effortlessly bruteforce most voicemail passwords without the phone's owner ever knowing. With that access, you could get an online account's password reset code and, consequently, control of the account itself.
And no, your two-factor authentication won't stop a hacker from resetting your password.
One of Vigo's slides laid out the basic structure of the attack:
1. Bruteforce voicemail system, ideally using backdoor numbers
2. Ensure calls go straight to voicemail (call flooding, OSINT, HLR)
3. Start password reset process using "Call me" feature
4. Listen to the recorded message containing the secret code
5. Profit!
A recorded demo he played on stage showed a variation of this attack on a PayPal account.
"In three, two, one, boom — there it is," Vigo said to audience applause. "We just compromised PayPal."
Vigo was careful to note that he responsibly disclosed the vulnerabilities to the affected companies, but got a less than satisfactory response from many. He plans to post a modified version of his code to Github on Monday.
Notably, he reassures us that he altered the code so that researchers can verify that it works, but also so that script kiddies won't be able to start resetting passwords left and right.
So, now that we know this threat exists, what can we do to protect ourselves? Vigo, thankfully, has a few suggestions.
First and foremost, disable your voicemail. If you can't do that for whatever reason, use the longest possible PIN code that is also random. Next, try not to provide your phone number to online services unless you absolutely have to for 2FA. In general, try to use authenticator apps over SMS-based 2FA.
But, really, the most effective of those options is shutting your voicemail down completely. Which, and let's be honest here, you've likely been looking for a reason to do anyway. You can thank Vigo for providing you with the excuse.
Topics Cybersecurity
Previous:Online Christian Martyrs
Next:Alternate Histories
PlayStation will lay off 900 employees, including 'Marvel's SpiderGoogle is shutting down the YouTube Kids app for TVSubstack finally has DMsSwole Jeff Bezos joins Instagram to tease his new ROCKET FACTORYWhat the Luddites can teach us about AI replacing workersBest leap day deals: Celebrate this rare day by scoring great savings on travel and home goodsStay in a free owlFishermen find an 18These creepy wormThat incredibly wellBest Apple Watch deals: 44mm SE at lowest price everNothing Phone 2a design revealed: Still transparent, still pretty coolUnlearning loneliness: How TikTok is rewriting the rules of connectionNYT's The Mini crossword answers for February 28NASA's drone killer does not play aroundAlmost 100,000 people were watching a fake Facebook Live of a tornado GIFGoogle and Mystery Science teamed up to give schools eclipse glassesThe largest animal ever to walk the Earth gets a nameBest TV deal: Smsung's The Frame TV is under $1,000 at AmazonThat incredibly well New Apple Watch will have a larger screen, better heart rate detection Google Calendar's 'working hours' are great for passive aggressiveness 'Aquaman' reveals Atlantis kingdoms with snapshot of the Fisherman King Marvel's 'Black Widow' gets one step closer to reality with a new director Taylor Swift and Calvin Harris make their breakup Twitter official Singapore now has vending machines that sell books Only a Photoshop battle can make this cool penguin even cooler Almost 80 percent of 2017's ICOs were scams I miss the days before everyone was addicted to streaming services FCC updates Emergency Alert System in effort to minimize false alarms These videos of the 'Queer Eye' cast reacting to their Emmy noms are making us ugly cry 'Fortnite' Season 5 is here with some big changes Real headlines from InfoWars, a site that's not banned on Facebook Buy a kiddie pool for your adult self this summer Of all the Kardashians, Kim lost the most Twitter followers Paul Ryan just wants Republicans to unite 'before the fall' Apple employee arrested for stealing self Rescue pit bull carefully tiptoes past sleeping cat These glamorous chickens are bringing back '80s chic Trump lost 100K followers just 15 minutes into the Twitter purge
1.7854s , 10123.359375 kb
Copyright © 2025 Powered by 【The Naughty New Mom Is My First Love Teacher (2025)】,Steady Information Network