A simple bypass made Box's multi-factor authentication redundant

Avast cybersecurity
(Image credit: Avast)

Cybersecurity researchers have helped fix an issue with Box that could have been exploited to bypass multi-factor authentication (MFA) for accounts that relied on authenticator apps such as Google Authenticator.

The popular cloud storage company was alerted by researchers at Varonis after they found a relatively simple workaround to use stolen credentials to log into a Box account without providing a time-based one-time password (TOTP).

According to the researchers, Box allowed users access to some areas of the account after verifying their login credentials, but before entering the TOTP. They demonstrated a mechanism that allowed them to unenroll a user from MFA after providing a username and password but before providing the second factor.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

“MFA is a step towards a safer internet and more resilient authentication for the SaaS [Software-as-a-Service] apps we rely on, but MFA isn’t perfect. There has been a massive push towards TOTP-based MFA, but if there are any flaws in its implementation, it can be bypassed,” point out the researchers.

Improper implementation 

In addition to demonstrating the workflow for bypassing TOTP to log into a compromised account, the researchers also took the opportunity to make a few suggestions for businesses looking to introduce MFA. 

For one, Varonis suggests that, in addition to requiring MFA, businesses must also use single sign-on (SSO) wherever possible. They also ask businesses to enforce strong password policies, avoid using questions with easy-to-find answers as part of their authentication flows, and keep their eyes peeled for breached passwords from their domain on sites like HaveIBeenPwnd

“The above example is simply one bypass technique for one SaaS platform. Many more exist—some of which we’ll publish soon,” conclude the researchers.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Security padlock in circuit board, digital encryption concept
MFA alone won’t protect you in 2025: the new cybersecurity imperative
Representational image of a shrouded hacker.
Getting to grips with Adversary-in-the-Middle threats
An abstract image of a lock against a digital background, denoting cybersecurity.
Building a resilient workforce security strategy
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
A person at a laptop with a cybersecure lock symbol floating above it.
A worrying security flaw could have left Microsoft SharePoint users open to attack
Latest in Pro
Nvidia GR00T N1 humanoid robot
Nvidia is dreaming of trillion-dollar datacentres with millions of GPUs and I can't wait to live in the Omniverse
Nvidia Isaac GROOT N1
“The age of generalist robotics is here" - Nvidia's latest GROOT AI model just took us another step closer to fully humanoid robots
A computer file surrounded by red laser beams
Free online file converters could infect your PC with malware, FBI warns
Nvidia Earth-2 weather models
Nvidia has updated its virtual recreation of the entire planet - and it could mean better weather forecasts for everyone
Nvidia DGX Station
Nvidia’s DGX Station brings 800Gbps LAN, the most powerful chip ever launched in a desktop workstation PC
Artificial intelligence India
Zoom launches AI Companion 2.0 with a major agent focus
Latest in News
Perplexity Squid Game Ad
New ad declares Squid Game's real winner is Perplexity AI
Pedro Pascal in Apple&#039;s Someday ad promoting the AirPods 4 with Active Noise Cancellation.
Pedro Pascal cures his heartbreak thanks to AirPods 4 (and the power of dance) in this new ad
Frank Grimes confronts Homer Simpson in The Simpsons&#039; Homer&#039;s Enemy episode
Disney+ adds a new continuous Simpsons stream, so you no longer have to spend ages choosing an episode
Helly and Mark standing on an artificial hill surrounded by goats in Severance season 2 episode 3
New Apple teaser for Severance season 2 finale suggests we might finally find out what Lumon is doing with those goats, and I don't think it's anything good
Nvidia GR00T N1 humanoid robot
Nvidia is dreaming of trillion-dollar datacentres with millions of GPUs and I can't wait to live in the Omniverse
Foldable iPhone
Apple’s first foldable iPhone could beat the Samsung Galaxy Z Fold 7 in one key way