{"id":177141,"date":"2025-10-16T01:13:04","date_gmt":"2025-10-16T01:13:04","guid":{"rendered":"https:\/\/teknomers.com\/en\/we-believed-that-two-step-authentication-apps-were-secure-but-researchers-have-demonstrated-how-easily-they-can-be-hacked\/"},"modified":"2025-10-16T01:13:06","modified_gmt":"2025-10-16T01:13:06","slug":"we-believed-that-two-step-authentication-apps-were-secure-but-researchers-have-demonstrated-how-easily-they-can-be-hacked","status":"publish","type":"post","link":"https:\/\/teknomers.com\/en\/we-believed-that-two-step-authentication-apps-were-secure-but-researchers-have-demonstrated-how-easily-they-can-be-hacked\/","title":{"rendered":"We believed that two-step authentication apps were secure, but researchers have demonstrated how easily they can be hacked."},"content":{"rendered":"\n<h2>The New Threat: Pixnapping and Two-Step Verification<\/h2>\n<p>Two-step verification with authentication apps is widely regarded as an <strong>essential method<\/strong> to protect our online accounts. However, recent research has unveiled a concerning new vulnerability. According to a report by <a rel=\"noopener, noreferrer nofollow\" href=\"https:\/\/arstechnica.com\/security\/2025\/10\/no-fix-yet-for-attack-that-lets-hackers-pluck-2fa-codes-from-android-phones\/?comments-page=1#comments\" target=\"_blank\">Ars Technica<\/a>, a group of researchers from multiple American universities has discovered a novel attack targeting Android devices that can capture these crucial codes in less than <strong>30 seconds<\/strong>\u2014the same amount of time it takes for the codes to refresh.<\/p>\n<p><!-- BREAK 1 --><\/p>\n<h2>Understanding Pixnapping<\/h2>\n<p><strong>Pixnapping<\/strong> is the term used to describe this alarming new attack method that can steal two-step authentication codes from apps like Google Authenticator or Microsoft Authenticator. Unlike SMS verification\u2014which can allow a window of 10 to 15 minutes for interception\u2014authentication apps refresh codes every 30 seconds, significantly increasing security. Yet, with this cutting-edge technique, researchers managed to crack the six-digit code in a mere 23 seconds, providing ample time for a hacker to access sensitive accounts.<\/p>\n<p><!-- BREAK 2 --><\/p>\n<div class=\"article-asset article-asset-normal article-asset-center\">\n<div class=\"desvio-container\">\n<div class=\"desvio\">\n<div class=\"desvio-figure js-desvio-figure\"><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<h2>How Pixnapping Works<\/h2>\n<p>So, how does this sophisticated attack function? Pixnapping operates through a sequence of three steps that can be executed by any app on Android without requiring special permissions:<\/p>\n<ol>\n<li>\n<p><strong>Initial Communication<\/strong>: The malicious app leverages Android APIs to communicate with the target app. It forces the target application to display specific data\u2014namely the authentication codes\u2014and sends this information to the Android rendering pipeline, responsible for displaying pixels on the screen.<\/p>\n<\/li>\n<li>\n<p><strong>Graphical Operations<\/strong>: Pixnapping then performs graphical analysis on the received pixel data. The attack identifies the coordinates of each pixel of interest and checks its color\u2014specifically whether it is white or non-white.<\/p>\n<\/li>\n<li>\n<p><strong>Timing Measurement<\/strong>: Interestingly, white pixels take less time to render than non-white pixels. By measuring the rendering time, Pixnapping can reconstruct images from the data captured from the render pipeline.<\/p>\n<\/li>\n<\/ol>\n<p><!-- BREAK 3 --><\/p>\n<h2>The Speed Factor<\/h2>\n<p><strong>Speed<\/strong> is crucial in the context of Pixnapping. While the attack can also acquire other types of visible information, such as <strong>account numbers<\/strong> or personal details, its rapid execution makes it particularly dangerous for authentication apps. By minimizing the number of samples collected per pixel, researchers have ingeniously decoded all six digits of the authentication code in just <strong>30 seconds<\/strong>.<\/p>\n<p><!-- BREAK 4 --><\/p>\n<h2>Vulnerable Devices<\/h2>\n<p>As noted earlier, Pixnapping specifically targets the Android operating system. The vulnerability appears to extend across multiple versions, as the investigation demonstrated that the attack was feasible on devices running Android versions from <strong>13 to 16<\/strong>. Though it has only been tested on Pixel phones and the Samsung Galaxy S25, the researchers suspect that most Android devices could be susceptible to this attack due to its underlying mechanism.<\/p>\n<p><!-- BREAK 5 --><\/p>\n<h2>Protecting Yourself<\/h2>\n<p>Currently, the best course of action is to remain vigilant while waiting for further updates from Google. While <a rel=\"noopener, noreferrer nofollow\" href=\"https:\/\/android.googlesource.com\/platform\/frameworks\/native\/+\/20465375a1d0cb71cdb891235a9f8a3fba31dbf6\" target=\"_blank\">Google has released a patch<\/a> to mitigate this vulnerability, early tests indicate that there are still methods to circumvent it. In a statement to <a rel=\"noopener, noreferrer nofollow\" href=\"https:\/\/www.theregister.com\/2025\/10\/13\/android_pixnapping_attack_captures_2fa_codes\/\" target=\"_blank\">The Register<\/a>, Google confirmed plans to issue a second patch in December aimed at fully addressing the vulnerability. Fortunately, the company has no evidence of malicious apps exploiting this security flaw, providing a sliver of reassurance.<\/p>\n<p>In summary, as our online lives become increasingly reliant on security measures such as two-step verification, understanding vulnerabilities like Pixnapping is crucial. By remaining informed and proactive, users can better protect their accounts while waiting for technological solutions. Just as importantly, as researchers continue to uncover flaws, it is imperative for both tech companies and users alike to work collaboratively to enhance digital security systems.<\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/teknomers.com\/category\/general\/\" rel=\"dofollow\">General News &#8211; 2<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The New Threat: Pixnapping and Two-Step Verification Two-step verification with authentication apps is widely regarded as an essential method to protect our online accounts. However, recent research has unveiled a concerning new vulnerability. According to a report by Ars Technica, a group of researchers from multiple American universities has discovered a novel attack targeting Android [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":177142,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36399],"tags":[11606,43700,8710,10142,6088,4135,761,4432,43699],"class_list":["post-177141","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-apps","tag-authentication","tag-believed","tag-demonstrated","tag-easily","tag-hacked","tag-researchers","tag-secure","tag-twostep"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/posts\/177141","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/comments?post=177141"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/posts\/177141\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/media\/177142"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/media?parent=177141"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/categories?post=177141"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/tags?post=177141"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}