2FA, was A Deep Dive on the Recent Widespread DNS Hijacking

Hunter Fuller hf0002+nanog at uah.edu
Wed Feb 27 04:02:05 UTC 2019


On Tue, Feb 26, 2019 at 9:56 PM Keith Medcalf <kmedcalf at dessus.com> wrote:
> I did write my own TOTP client.  However, why do you assume that I am talking about a TOTP client and not the referred webpage which requires the unfettered execution of third-party (likely malicious) javascript in order to view?  Not to mention requiring the use of (also quite possibly malicious) downloaded fonts?

Well, because:
1. the page's <noscript> tag points to the github repo which contains
the raw data in a fairly readable form; and
2. the page works fine in Lynx despite the warning.



More information about the NANOG mailing list