Boogie (fat nerd guy) gets banned on YT

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

John Connor

Lifer
Nov 30, 2012
22,840
617
121
Wouldn't have worked if he did 2FA with an authenticator app and time based cypher.


Aren't all 2FA Apps time based? Meaning you have to enter the code in about 20 seconds until you get a new one and the old code doesn't work?
 

Mark R

Diamond Member
Oct 9, 1999
8,513
14
81
.. i dont even know what that means ...

Prior to SMS 2FA, the conventional way of 2FA was to use a dongle device.

The device had a clock in it, a secret key, and an encryption engine. The device would take the date/time to the nearest minute, encrypt it with the key, and display the result on an LCD. The remote server would calculate the code using the same method, and would verify the code you entered to ensure it matched. (The process is slightly more involved, to allow for the time on the dongle to drift a bit, but that's basically it).

These days, you can get apps which do the same thing. They run on a smart device, and use the date/time and a secret key to generate a short-lived code.
 

Anubis

No Lifer
Aug 31, 2001
78,716
417
126
tbqhwy.com
Unreal! After responding to the two-factor thread I was in the pool thinking about how a hacker could circumvent that and wondered if Telcos could be hacked and lo and behold we have a perfect example right here!

considering Verizon just gave out his info 2FA wasn't gonna do shit
 

Ichinisan

Lifer
Oct 9, 2002
28,298
1,234
136
considering Verizon just gave out his info 2FA wasn't gonna do shit

A non-SMS implementation of 2FA (Authenticator app with time-based cypher) would have done just fine.

I use Google Authenticator with various services including Gmail, Hotmail, and Dropbox.
 

Anubis

No Lifer
Aug 31, 2001
78,716
417
126
tbqhwy.com
verizon gave someone access to his phone account
dude changed phone sim to his
2 factor now sends auth to hackers phone


that is exactly what happened
as Ichinisan said it would not have happened with some other form of 2FA but pmuch everyone uses SMS based
 

KeithP

Diamond Member
Jun 15, 2000
5,660
198
106
there are two interesting bits of info here. one, that a hacker has managed to get access to his account, through youtube exploits, meaning google's awesome security is actually breachable.

second, there are no humans supervising the bans on youtube.

What youtube exploits are you talking about? The guy posted the following on reddit…
Hey guys. Boogie here.
Looks like we got hacked again. Someone manage to steal my phone number and used it to gain access to everything.

That sounds to me like he was using multi factor authentication and instead of using the Google Authenticator app, he used text messaging to his phone. His mistake. Plus notice he said "hacked again." Clearly this guy doesn't have a clue about security.

This info was in the video link posted.

-KeithP
 

Aikouka

Lifer
Nov 27, 2001
30,383
912
126
That sounds to me like he was using multi factor authentication and instead of using the Google Authenticator app, he used text messaging to his phone. His mistake. Plus notice he said "hacked again." Clearly this guy doesn't have a clue about security.

GMail allows you to add a phone number for account recovery purposes. The hacker was able to steal his Verizon number using social engineering (it would be interesting to see how the hacker convinced Verizon), and then used the account recovery to gain access to his Google account. Since the Google account is tied to various other services such as YouTube, it isn't that hard to screw with things, and since Boogie makes his money off YouTube, that's a serious thing to screw with.

I recall Ars having an article on something similar to this happening to one of their writers. In that case, I think it was someone stealing information through Amazon by constantly fishing for bits of information.
 

Anubis

No Lifer
Aug 31, 2001
78,716
417
126
tbqhwy.com
GMail allows you to add a phone number for account recovery purposes. The hacker was able to steal his Verizon number using social engineering (it would be interesting to see how the hacker convinced Verizon), and then used the account recovery to gain access to his Google account. Since the Google account is tied to various other services such as YouTube, it isn't that hard to screw with things, and since Boogie makes his money off YouTube, that's a serious thing to screw with.

I recall Ars having an article on something similar to this happening to one of their writers. In that case, I think it was someone stealing information through Amazon by constantly fishing for bits of information.

it was a guy at Wired but close enough, and it was apple that fed as well as amazon. IIRC it all came about because he had a really unique twitter ID or something and people wanted it


http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/
 
Last edited:

foghorn67

Lifer
Jan 3, 2006
11,885
53
91
verizon gave someone access to his phone account
dude changed phone sim to his
2 factor now sends auth to hackers phone


that is exactly what happened
as Ichinisan said it would not have happened with some other form of 2FA but pmuch everyone uses SMS based
Setup a verbal password with your network provider. Anybody that requests changes to the account will need a password.

Sent from my SM-G930T using Tapatalk
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |