Live data from Hacker News

Our Copyfish extension was stolen and adware-infested

a9t9.com

1–10 of 217 posts

Re: Our Copyfish extension was stolen and adware-infested

#6

I'd have though that two-factor authentication could have prevented this type of attack?

It could, and the plugin creators regret not having it active for everyone's account:

> Sigh... totally agree. I could add a longer story why just this account had no 2FA enabled, but the lesson learned is simple: From now on, we enable 2FA for every account that offers it.

So they won't make this mistake again.

Re: Our Copyfish extension was stolen and adware-infested

#8
post #6

I'd have though that two-factor authentication could have prevented this type of attack?

It could, and the plugin creators regret not having it active for everyone's account: > Sigh... totally agree. I could add a longer story why just this account had no 2FA enabled, but the lesson learned is simple: From now on, we enable 2FA for every account that offers it. So they won't make this mistake again.

Thanks - saw it now in the comments.

Re: Our Copyfish extension was stolen and adware-infested

#9
post #3

I'd have though that two-factor authentication could have prevented this type of attack?

Not if the phising site asks for the 2FA token.

The point of 2FA is challenge-response and the secret key is in the token. If a phishing site asks for 2FA it can get only one valid challenge-response pair, not the secret key.

Re: Our Copyfish extension was stolen and adware-infested

#10
> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen.

First, it is excellent that you disclosed the issue.

Second, based upon the quoted text you really aren't accepting responsibility for having been phished. The team member wasn't "unlucky." Your "radar" shouldn't trick you into thinking you won't be attacked.

Post reply on HN