# Google Authenticator 如何使一家公司的网络漏洞变得更加严重

Source: https://www.zaihua.news/article/20362/

[返回新闻流](https://www.zaihua.news/)
2023年9月17日 · 01:04 · [在花新闻](https://www.zaihua.news/about/)

# Google Authenticator 如何使一家公司的网络漏洞变得更加严重

Retool公司[披露](https://retool.com/blog/mfa-isnt-mfa/)了其客户支持系统遭到入侵的情况，攻击者通过谷歌身份验证器（Google Authenticator）的同步功能入侵了27个加密货币行业的客户账户。

攻击始于一名员工点击了一条短信中的链接，泄露了谷歌身份验证器中的密码和临时一次性密码。攻击者还通过电话获取了额外的多因素代码，并添加了自己的设备到员工的Okta账户中。

谷歌最近发布的[谷歌身份验证器同步](https://arstechnica.com/security/2023/09/how-google-authenticator-gave-attackers-one-companys-keys-to-the-kingdom/%E2%80%8B%E2%80%8Bhttps://security.googleblog.com/2023/04/google-authenticator-now-supports.html?ref=retool.com)功能 ，可将 MFA 代码同步到云端。如 [Hacker News](https://news.ycombinator.com/item?id=35690398&ref=retool.com) 指出的那样 ，这是非常不安全的，因为如果你的 Google 帐户被泄露，那么你的 MFA 代码也会被泄露。

Retool指出，谷歌身份验证器的同步功能加剧了入侵的严重性，呼吁谷歌删除该功能或提供禁用选项。同时还强调[FIDO2](https://fidoalliance.org/fido2/)规范的多因素身份验证是安全的标准，而基于TOTP的身份验证容易受到网络钓鱼攻击。

参考：[Retool](https://retool.com/blog/mfa-isnt-mfa/)；[Ars Technica](https://arstechnica.com/security/2023/09/how-google-authenticator-gave-attackers-one-companys-keys-to-the-kingdom/%E2%80%8B%E2%80%8Bhttps://security.googleblog.com/2023/04/google-authenticator-now-supports.html?ref=retool.com)
来源：[Ars Technica](https://arstechnica.com/security/2023/09/how-google-authenticator-gave-attackers-one-companys-keys-to-the-kingdom/)

Via [Daneel God](https://t.me/Daneel%20God)

投稿：[@ZaiHuaBot](https://t.me/ZaiHuaBot)
频道：[@TestFlightCN](https://t.me/TestFlightCN)

[上一条苹果高管接受 IGN 采访：iPhone 15 Pro 将成为“最好的游戏机”](https://www.zaihua.news/article/20361/)[下一条2023年上半年全国登记结婚392.8万对](https://www.zaihua.news/article/20364/)
