Even 2-factor is susceptible to social engineering. Years ago when I worked IT for a company the protocol for providing a 24hr bypass to their RSA token was to ask generic questions that any 'friend' could likely answer. We'd use this if they were working from home and left their token at work or the other way around.
That's badly implemented 2-factor, though. If you have a system that allows you to bypass a protocol, then of course it will be easier to... bypass that protocol.
There was that guy that outsourced his own job to a developer in China so he could surf Reddit and HN all day at work. If I recall he even FedEx'ed his two-factor auth to the guy in China so he could VPN in and complete his work.
I remember that guy getting caught from some OPSEC weaknesses though. He would have been better off if the Chinese replacement was logging in though a machine at the guy's house, so the IP address didn't give it away. You could also use a webcam to share the RSA token, without having to physically send it, and lose control of it.
Comments
Even 2-factor is susceptible to social engineering. Years ago when I worked IT for a company the protocol for providing a 24hr bypass to their RSA token was to ask generic questions that any 'friend' could likely answer. We'd use this if they were working from home and left their token at work or the other way around.
That's badly implemented 2-factor, though. If you have a system that allows you to bypass a protocol, then of course it will be easier to... bypass that protocol.
There was that guy that outsourced his own job to a developer in China so he could surf Reddit and HN all day at work. If I recall he even FedEx'ed his two-factor auth to the guy in China so he could VPN in and complete his work.
I remember that guy getting caught from some OPSEC weaknesses though. He would have been better off if the Chinese replacement was logging in though a machine at the guy's house, so the IP address didn't give it away. You could also use a webcam to share the RSA token, without having to physically send it, and lose control of it.