Live data from Hacker News

Our Copyfish extension was stolen and adware-infested

a9t9.com

11–20 of 217 posts

Re: Our Copyfish extension was stolen and adware-infested

#11
post #10

> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…

[deleted]

Re: Our Copyfish extension was stolen and adware-infested

#12
post #3

Earlier quoted context omitted.

Not if the phising site asks for the 2FA token.

The point of 2FA is challenge-response and the secret key is in the token. If a phishing site asks for 2FA it can get only one valid challenge-response pair, not the secret key.

[deleted]

Re: Our Copyfish extension was stolen and adware-infested

#13
post #3

Earlier quoted context omitted.

Not if the phising site asks for the 2FA token.

The point of 2FA is challenge-response and the secret key is in the token. If a phishing site asks for 2FA it can get only one valid challenge-response pair, not the secret key.

That still allows them to log in though.

Re: Our Copyfish extension was stolen and adware-infested

#14
post #10

> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…

While I normally agree, I think it's important that they referred to the specific person without using blaming language. The team failed and screwed up because they had bad policies with their account. The individual team member who was holding the keys when the screw-up happened? Unlucky.

Fix the process, not the people.

It's good that they're not throwing the poor person under the bus.

Re: Our Copyfish extension was stolen and adware-infested

#15
post #10

> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…

Accepting responsibility for being a victim of phishing? That could happen to the best of us.

Re: Our Copyfish extension was stolen and adware-infested

#16
post #10

> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…

Accepting responsibility for being a victim of phishing? That could happen to the best of us.

And it has. Part of my infosec career was spent phishing devs. Everyone scoffs at it until it happens to them. It's quite effective.

Re: Our Copyfish extension was stolen and adware-infested

#18
post #14
post #10

> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…

While I normally agree, I think it's important that they referred to the specific person without using blaming language. The team failed and screwed up because they had bad policies with their account. The individual team member who was holding the keys when the screw-up happened? Unlucky. Fix the process, not the people. It's good that they're not throwing the poor person under the bus.

I don't think more policies will make a better place. One of the team member screw up and stuff like this happen. I am questioning his security education to have been phished so easily.

Re: Our Copyfish extension was stolen and adware-infested

#19

Good reminder that you should never be in the mindset of "expecting" a phish from any source - trust is how they get you. Also, if a message was really urgent, you wouldn't have to click-through to see it.

I think I'm misreading your comment, but the best defense against phishing is to always be expecting a phishing attack from every source. Every time you're about to paste your password, glance at the url bar.

Re: Our Copyfish extension was stolen and adware-infested

#20

Earlier quoted context omitted.

Accepting responsibility for being a victim of phishing? That could happen to the best of us.

And it has. Part of my infosec career was spent phishing devs. Everyone scoffs at it until it happens to them. It's quite effective.

Likewise. I just hate this attitude of "they should nhave known better".
Post reply on HN