Уровень 0 · материалов: 3
В кластер входят документы о дырах в безопасности при доставке секретных кодов физической почтой; документы о чисто цифровых атаках без физического компонента сюда не относятся.
Общие признаки: перехват PIN-кодов через почту, кража личности, недостатки физической безопасности конвертов, несанкционированный доступ к аккаунтам
Группа выше: Атаки на мобильные устройства и периферию
Смысл: The text points out a security vulnerability in Google's physical PIN delivery system for AdWords, where the code is visible through the envelope's window, potentially allowing postal employees to steal it.
The author discovers that Google AdWords PIN codes are visible through the envelope window, making them susceptible to theft by postal workers.
Смысл: The text reveals a critical security flaw in VTB24's PIN delivery system where the PIN is mirrored on the envelope's inner coating, warning users to destroy such envelopes to prevent theft.
An author discovered that VTB24 bank PIN envelopes leave a visible imprint of the PIN on the envelope itself, posing a serious security risk if not destroyed.
Смысл: The text demonstrates that technical security measures on a government portal are rendered useless if the physical verification process (postal delivery) relies on negligent human behavior, allowing for easy identity theft and unauthorized account registration.
A cybersecurity expert proves that Gosuslugi.rf is vulnerable to identity theft because the physical mail confirmation process fails to properly verify passports.