Post #4398371
2026-08-05 23:08 UTC
@foone@digipres.club
The Zeus trojan used to lie in wait watching for a banking login, then launching a second session in the background using your existing fresh session cookie. You log in and do whatever - and it's in the background transferring your funds away.
The second MFA is intended to confirm that it's still you doing the transaction and not a bot that stole your session.
There are better ways to auth and secure a session now, but those kind of countermeasures tend to get written into policy, especially in places like banking, and are requirements long after they cease to be useful.
Replies (0)
No replies.