Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ExampleCo staff won't / will ask for this code. #14

Open
wgknowles opened this issue Sep 8, 2021 · 0 comments
Open

ExampleCo staff won't / will ask for this code. #14

wgknowles opened this issue Sep 8, 2021 · 0 comments

Comments

@wgknowles
Copy link

OTP codes have two common use cases:

  1. Verifying the identity of a user that contacts the support team (phone / chat)
  2. Verifying the identity of a user logging in / performing step-up authentication on a system

Malicious actors very commonly get in touch with an end-user under the guise of being a legitimate support team member and ask the end-user to provide the OTP code that they just sent. Appending the following text will serve as a mitigation to users falling for this attack vector:

  1. "ExampleCo staff will ask for this code"
  2. "ExampleCo staff will NOT ask for this code"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant