nanog mailing list archives

Re: 2FA, was A Deep Dive on the Recent Widespread DNS Hijacking


From: Hunter Fuller <hf0002+nanog () uah edu>
Date: Tue, 26 Feb 2019 22:02:05 -0600

On Tue, Feb 26, 2019 at 9:56 PM Keith Medcalf <kmedcalf () dessus com> wrote:
I did write my own TOTP client.  However, why do you assume that I am talking about a TOTP client and not the 
referred webpage which requires the unfettered execution of third-party (likely malicious) javascript in order to 
view?  Not to mention requiring the use of (also quite possibly malicious) downloaded fonts?

Well, because:
1. the page's <noscript> tag points to the github repo which contains
the raw data in a fairly readable form; and
2. the page works fine in Lynx despite the warning.


Current thread: