Live data from Hacker News

Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

wordfence.com

31–40 of 49 posts

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#31

"Changing your password every few months is good practice in general." Stop saying that! https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-r...

I still stand by "change your passwords often".

You never know when somebody has access to your accounts. I learned the hard way that someone had access to my Facebook because they watched me type on the keyboard. Had I changed my password monthly, I would have kicked him out after 30 days. As it stand, that person had access to my account for at least a year if not more.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#32

"Changing your password every few months is good practice in general." Stop saying that! https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-r...

I still stand by "change your passwords often". You never know when somebody has access to your accounts. I learned the hard way that someone had access to my Facebook because they watched me type on the keyboard. Had I changed my password monthly, I would have kicked him out after 30 days. As it stand, that person had access to my account for at least a year if not more.

You didn't have login alerts or approvals enabled? Those would've alerted you to the need for a password rotation instantly without needing to rotate complex passwords on a regular cadence.

If anything, I'd say your comment hardened my position against password rotation given how many mainstream sites with sensitive data expose extra security measures to their users. Take advantage of all of them!

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#33
post #32

Earlier quoted context omitted.

I still stand by "change your passwords often". You never know when somebody has access to your accounts. I learned the hard way that someone had access to my Facebook because they watched me type on the keyboard. Had I changed my password monthly, I would have kicked him out after 30 days. As it stand, that person had access to my account for at least a year if not more.

You didn't have login alerts or approvals enabled? Those would've alerted you to the need for a password rotation instantly without needing to rotate complex passwords on a regular cadence. If anything, I'd say your comment hardened my position against password rotation given how many mainstream sites with sensitive data expose extra security measures to their users. Take advantage of all of them!

You don't get login alerts if the person is using your wi-fi, a wi-fi where you once logged in (college, university, work...) or simply a computer you logged in one time (at that friend's place). That person could even disable them and you wouldn't be aware of it.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#35

Does a password manager like 1Password catch that the URL is incorrect in these cases?

No. How would it know what the correct one is? They would refuse to autofill it though, because the URL wouldn't match anything for any logins stored.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#36

Does a password manager like 1Password catch that the URL is incorrect in these cases?

1Password will pop up a warning if the url you originally saved the credentials for is different when trying to fill in the form.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#37
I don't know if this is interesting or helpful, but I made a Chrome extension for helping test email information in Gmail. It would probably help in this instance to notify somewhat that something isn't correct.

I updated it after my initial upload to enable links (defaults to no links but can click a button to enable links). I just haven't gotten around to re-uploading the plugin. After some thought I definitely feel that just removing links altogether was too much. I will update the plugin after work.

PhishBlock Chrome plugin: https://chrome.google.com/webstore/detail/phishblock/mfigocg...

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#39

This is crazy. It's 2017. Why are people STILL clicking links in their E-mail? Have people learned nothing? You don't have to be a "technical user" anymore know know that's a bad idea. Hell, why do major E-mail clients even allow functional hyperlinks in E-mail? The major E-mail clients could 80% solve phishing overnight by just disabling links. They could probably solve a further 10% by disallowing copying things th…

Links are pretty integral to the web. If it wasn't email, it would be Slack or social media. Mobile makes the problem worse because you click a big button which scrapes the link and thus can be gamed to look legitimate.

"Design for default-secure" ought to be UX rule #1.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#40
post #21

Earlier quoted context omitted.

Pssh, I'll say it - I'd fall for this, more than 0% of the time. Am I an advanced user? I can try to give you an example of some client side TLS thing I have implemented and we can haggle over where the bar is for "advanced", but give me a Saturday night beer-riddled netflix binge and a midnight email check, I'm clicking this link. I'd hope my 2FA would freak out, around that point, and save me from myself. I guess i…

You'd probably notice because that page would not ask about the 2FA.

By default, Google remembers your device for a number of weeks and does not ask for 2FA multiple times on it.
Post reply on HN