WhisperX tag archive

#2fa

This page collects WhisperX intelligence signals tagged #2fa. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-01 04:27:00 · GitHub Issues

1. Kratos TOTP Security Flaw: Client-Side Counter Allows Brute-Force Attack on 2FA

A critical security vulnerability in the Kratos identity management system allows attackers to bypass two-factor authentication (2FA) protections. The flaw resides in the current TOTP (Time-based One-Time Password) login challenge, which uses a client-controlled cookie to track failed verification attempts. Because the...

The Lab · 2026-04-29 00:54:11 · GitHub Issues

2. Timing Side-Channel Exposes Trusted Device Tokens in Authentication Service

A timing attack vulnerability has been identified in the trusted device verification logic of a production authentication service, creating a potential vector for adversaries to enumerate valid device tokens by measuring response latency differentials. The flaw resides in the isTrustedDevice method within src/auth/two-...