Live data from Hacker News

Our Copyfish extension was stolen and adware-infested

a9t9.com

21–30 of 217 posts

Re: Our Copyfish extension was stolen and adware-infested

#21
post #3

Earlier quoted context omitted.

Not if the phising site asks for the 2FA token.

The point of 2FA is challenge-response and the secret key is in the token. If a phishing site asks for 2FA it can get only one valid challenge-response pair, not the secret key.

One login is enough to authorize an Oauth app.

Re: Our Copyfish extension was stolen and adware-infested

#22
post #14

Earlier quoted context omitted.

While I normally agree, I think it's important that they referred to the specific person without using blaming language. The team failed and screwed up because they had bad policies with their account. The individual team member who was holding the keys when the screw-up happened? Unlucky. Fix the process, not the people. It's good that they're not throwing the poor person under the bus.

I don't think more policies will make a better place. One of the team member screw up and stuff like this happen. I am questioning his security education to have been phished so easily.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you.

The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game.

A policy of popping up a popup "glance at url bar" every time you copy your password from your password manager (which you're using, right?) would go a long way.

Re: Our Copyfish extension was stolen and adware-infested

#23

Good reminder that you should never be in the mindset of "expecting" a phish from any source - trust is how they get you. Also, if a message was really urgent, you wouldn't have to click-through to see it.

I think I'm misreading your comment, but the best defense against phishing is to always be expecting a phishing attack from every source. Every time you're about to paste your password, glance at the url bar.

I read it as, “you should never be in the mindset of ‘expecting’ a phish from any [specific] source.”

I think OP agrees with you.

Re: Our Copyfish extension was stolen and adware-infested

#24

Earlier quoted context omitted.

I don't think more policies will make a better place. One of the team member screw up and stuff like this happen. I am questioning his security education to have been phished so easily.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

Lastpass will tell you whether it recognizes the site when you go to fill in the password (yes, I use it despite the scary stuff, I know I probably should switch to OnePassword).

Do other password managers not do that?

Just curious, not trying to engage the bigger question of whether getting phished is the user's fault.

Re: Our Copyfish extension was stolen and adware-infested

#25

Earlier quoted context omitted.

I don't think more policies will make a better place. One of the team member screw up and stuff like this happen. I am questioning his security education to have been phished so easily.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

An email from Google with a bit.ly link? Hell no, I hope I won't fell from it in whatever situation.

I agree that any defense is far from being perfect, but IT professionals shouldn't fell for an unsofiscated attack like this even if you are no working in security. I am not even talking about a web developer.

Re: Our Copyfish extension was stolen and adware-infested

#26

Good reminder that you should never be in the mindset of "expecting" a phish from any source - trust is how they get you. Also, if a message was really urgent, you wouldn't have to click-through to see it.

I think I'm misreading your comment, but the best defense against phishing is to always be expecting a phishing attack from every source. Every time you're about to paste your password, glance at the url bar.

Password managers with browser extensions are a good fix for this too. If you're used to entering your password only through the extension, not being able to do that on a login screen would be a big warning sign. Admittedly, these extensions have had some vulnerabilities in the past, but phishing is simply a bigger problem for the vast majority of users.

Obviously, for sites that support U2F (like Google), getting a YubiKey or any other U2F-compatible key would be the best protection against this.

Re: Our Copyfish extension was stolen and adware-infested

#27

Earlier quoted context omitted.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

Lastpass will tell you whether it recognizes the site when you go to fill in the password (yes, I use it despite the scary stuff, I know I probably should switch to OnePassword). Do other password managers not do that? Just curious, not trying to engage the bigger question of whether getting phished is the user's fault.

I use KeepassX, mostly because it's small and nearly impossible to attack. But I understand the desire for convenience, and as you say, there are some advantages to other managers.

Re: Our Copyfish extension was stolen and adware-infested

#28

Good reminder that you should never be in the mindset of "expecting" a phish from any source - trust is how they get you. Also, if a message was really urgent, you wouldn't have to click-through to see it.

I think I'm misreading your comment, but the best defense against phishing is to always be expecting a phishing attack from every source. Every time you're about to paste your password, glance at the url bar.

I think you're both right - they way I read their comment was more like "if you expect a phishing attack from certain sources, this implies you're not on the defensive against attacks which aren't from those sources".

Re: Our Copyfish extension was stolen and adware-infested

#29

Earlier quoted context omitted.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

An email from Google with a bit.ly link? Hell no, I hope I won't fell from it in whatever situation. I agree that any defense is far from being perfect, but IT professionals shouldn't fell for an unsofiscated attack like this even if you are no working in security. I am not even talking about a web developer.

And you would be wrong about that. They do. All the time. Spear phishing is still the most effective way for foreign nationals to breach US companies.

Now, there are two ways to deal with the situation. Demonize, or accept. The demonize/blame approach doesn't work.

Re: Our Copyfish extension was stolen and adware-infested

#30

Earlier quoted context omitted.

I don't think more policies will make a better place. One of the team member screw up and stuff like this happen. I am questioning his security education to have been phished so easily.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

> The only real defense is to glance at the url bar every time you're about to enter your password.

With i18n not even that: https://www.theguardian.com/technology/2017/apr/19/phishing-...

Benign POC: https://www.xn--80ak6aa92e.com/ (open it and it'll look like a normal "l" in the url box)

Post reply on HN