NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Juha Saarinen: Another security hoop to jump through

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
15 Jan, 2019 04:00 PM3 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Take over someone's email address, and it's very likely you'll get access to heaps more than just their personal and professional correspondence. Photo / Getty Images

Take over someone's email address, and it's very likely you'll get access to heaps more than just their personal and professional correspondence. Photo / Getty Images

COMMENT: It is time for another reminder that email continues to be a threat vector despite numerous attempts at securing the internet-borne service that the vast majority of us use.

Take over someone's email address, and it's very likely you'll get access to heaps more than just their personal and professional correspondence.

A compromised email account can open the door to multiple services that use the address as the login name, a bad practice that refuses to die.

Thanks to massive data breaches over the past few years, hackers probably know your email already and maybe your password too.

The way to stop attackers from breaking into your account is two-factor authentication (2FA) which means you enter your login credentials, and then a unique, single-use code that's either sent to you via a different channel, or an app.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Without the correct code, nobody can log in to your account.

Where there's a will there's a way though. At the beginning of the year, a Polish developer released an elegant tool called Modlishka (Mantis) that takes bypassing 2FA very simple indeed.

Modlishka is used in phishing attacks whereby targets are sent a link that looks like it leads to a legitimate, known and trusted website like Gmail.

Advertisement
Advertise with NZME.

Instead, the link goes to the attackers site which is an indistinguishable digital copy of the real one.

Next, users are asked to log in and enter the 2FA code that Modlishka passes on to the real site and receives a token that logs in both the target and the attacker. You can guess what happens next.

Phishing with Modlishka (bypass 2FA) from Piotr Duszynski on Vimeo.

Security researchers I spoke to said that while a fair bit of tweaking is necessary to counter Google and other providers changing their threat detection heuristics, Modlishka works and isn't even new. Similar software is already in use by infosec testers, and also by "Advanced Persistent Threat" (ATP) or nation-state hackers.

Discover more

Business

Controversial law that's set Aussie's tech industry on fire

11 Dec 04:00 PM
Business

Why it's likely you have been hacked

18 Dec 04:00 PM
Opinion

Four big tech predictions for 2019

23 Dec 02:23 AM
Telecommunications

Tech is a loaded gun

08 Jan 03:43 AM

The standard advice here is to check the link or uniform resource locator (URL) to make sure that your browser connects to the right site. However, phishers work around that by using áçćêńtęd and non-English language characters in URLs, which can be very hard to spot.

Since it's almost impossible to exist on the internet without an email address, what can you do to protect yourself against Modlishka and similar phishing tools?

First, keep on using 2FA for all your logins. Despite the weaknesses above, 2FA makes it much harder to take over your accounts, which is why attackers have to create deceptions like Modlishka.

Second and this is what security industry professionals recommend, start using hardware tokens or keys to authenticate yourself.

Popular web browsers such as Google Chrome, Microsoft Edge, Mozilla Firefox and Opera support the FIDO Alliance Universal 2nd Factor (U2F) standard, and so do other services.

Then you'll need to fork out $55-$75 for a compatible hardware device from companies such as Yubico or Google, enable U2F, swear quietly over the additional login complication and making sure that you have a backup key in case you lose the original one.

Advertisement
Advertise with NZME.

Hardware keys bump up your login security considerably, but they're not invulnerable.

Somewhere out there a creative person will spot a non-obvious way to get around hardware key protection through weaknesses in perhaps not the devices themselves but the systems they connect to.

Either that, or an attacker will simply contact tech support, pretend to be you and ask them to turn off 2FA on your account. Ah well; at least you tried.

Save

    Share this article

Latest from Business

Premium
Shares

Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

18 Jun 06:09 AM
Premium
Business

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
New Zealand

'Life-changing': International flights return to Hamilton Airport

18 Jun 05:23 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

18 Jun 06:09 AM

The S&P/NZX 50 Index closed down 0.10%, falling to 12,627.32.

Premium
Fringe Benefit Tax: Should you be paying it if your business owns a ute?

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
'Life-changing': International flights return to Hamilton Airport

'Life-changing': International flights return to Hamilton Airport

18 Jun 05:23 AM
Premium
Liam Dann: 'Brick wall' – why tomorrow’s GDP data won’t tell the real story

Liam Dann: 'Brick wall' – why tomorrow’s GDP data won’t tell the real story

18 Jun 05:17 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP