> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…
Our Copyfish extension was stolen and adware-infested
11–20 of 217 posts
Re: Our Copyfish extension was stolen and adware-infested
#12Re: Our Copyfish extension was stolen and adware-infested
#13Earlier quoted context omitted.
Not if the phising site asks for the 2FA token.
The point of 2FA is challenge-response and the secret key is in the token. If a phishing site asks for 2FA it can get only one valid challenge-response pair, not the secret key.
Re: Our Copyfish extension was stolen and adware-infested
#14> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…
Fix the process, not the people.
It's good that they're not throwing the poor person under the bus.
Re: Our Copyfish extension was stolen and adware-infested
#15> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…
Re: Our Copyfish extension was stolen and adware-infested
#16> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…
Accepting responsibility for being a victim of phishing? That could happen to the best of us.
Re: Our Copyfish extension was stolen and adware-infested
#17Re: Our Copyfish extension was stolen and adware-infested
#18> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…
While I normally agree, I think it's important that they referred to the specific person without using blaming language. The team failed and screwed up because they had bad policies with their account. The individual team member who was holding the keys when the screw-up happened? Unlucky. Fix the process, not the people. It's good that they're not throwing the poor person under the bus.
Re: Our Copyfish extension was stolen and adware-infested
#19Good reminder that you should never be in the mindset of "expecting" a phish from any source - trust is how they get you. Also, if a message was really urgent, you wouldn't have to click-through to see it.
Re: Our Copyfish extension was stolen and adware-infested
#20Earlier quoted context omitted.
Accepting responsibility for being a victim of phishing? That could happen to the best of us.
And it has. Part of my infosec career was spent phishing devs. Everyone scoffs at it until it happens to them. It's quite effective.