| ▲ | nunez 2 hours ago | |
A family member installed an app into their Android phone from the Play Store. It was innocent enough until it asked for a truckload of permissions, like being able to change the launcher, which they ofc tapped "Allow" to since permission request fatigue is real and still a bit of an unsolved problem. So the app delivered on its promise and changed their phone's launcher. It had a fake Gmail widget that showed them their mail but, of course, wasn't actually tied to the actual Gmail app and was an easy way of getting a refresh token for their account. Bingo bango bongo: their email was now at risk. They changed their password after I told them to right away upon them asking me to look at their phone because "it was slow." > Magic link auth isn't any less secure than any site that has a password-reset flow. Which is exactly the problem. Cloning someone's SIM/eSIM and immediately performing password resets is a well-known security issue. | ||
| ▲ | kyle-rb 35 minutes ago | parent | next [-] | |
> Cloning someone's SIM Yeah I don't trust SMS either, that's why I said email. You can do a lot more to protect your email account than your phone number. It's very disconcerting to think about how many malicious apps like that must exist in the Play Store, but again, gaining access to someone's Google account is still game over if that's how you're syncing passkeys. | ||
| ▲ | dsl 2 hours ago | parent | prev [-] | |
If you are blanket accepting permissions passkeys do nothing to fix the attack you describe (on device phishing). | ||