A simple bypass made Box’s multi-factor authentication redundant



    Cybersecurity researchers have helped fix an issue with Box that could have been exploited to bypass multi-factor authentication (MFA) for accounts that relied on authenticator apps such as Google Authenticator.

    The popular cloud storage company was alerted by researchers at Varonis after they found a relatively simple workaround to use stolen credentials to log into a Box account without providing a time-based one-time password (TOTP).



    Source link