Live data from Hacker News

Our Copyfish extension was stolen and adware-infested

a9t9.com

61–70 of 217 posts

Re: Our Copyfish extension was stolen and adware-infested

#61

Earlier quoted context omitted.

> Every time you're about to paste your password, glance at the url bar. Actually - I disagree with this. You can no longer "glance" at the url bar to determine if you are on the right domain due to Unicode chars if you clicked a link. The only safe way is to type the url yourself into the browser. If it is a long link - then at least typing the base domain, and pasting the "rest" is probably safe?

This actually isn't true. A website like https://www.xn--80ak6aa92e.com/ won't show up as apple.com. Browsers don't allow Unicode rendering in the URL bar. Maybe IE is affected though. I haven't tested every browser. But it's a known security concern.

Sorry to tell you, does show up as apple.com in my browser. Chrome 52.0.2743.82-1 on Arch x86_64.

Re: Our Copyfish extension was stolen and adware-infested

#62
post #61

Earlier quoted context omitted.

This actually isn't true. A website like https://www.xn--80ak6aa92e.com/ won't show up as apple.com. Browsers don't allow Unicode rendering in the URL bar. Maybe IE is affected though. I haven't tested every browser. But it's a known security concern.

Sorry to tell you, does show up as apple.com in my browser. Chrome 52.0.2743.82-1 on Arch x86_64.

[deleted]

Re: Our Copyfish extension was stolen and adware-infested

#63
post #41

Earlier quoted context omitted.

> The only real defense is to glance at the url bar every time you're about to enter your password. With i18n not even that: https://www.theguardian.com/technology/2017/apr/19/phishing-... Benign POC: https://www.xn--80ak6aa92e.com/ (open it and it'll look like a normal "l" in the url box)

Browser shows https://www.xn--80ak6aa92e.com to me, Chrome on Android. What browser are you using that shows non-ascii with .com?

Firefox for android at least shows it as Unicode

Re: Our Copyfish extension was stolen and adware-infested

#64

Earlier quoted context omitted.

I don't think more policies will make a better place. One of the team member screw up and stuff like this happen. I am questioning his security education to have been phished so easily.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

That's a good habit, but a good tool to help you avoid getting phished is https://support.google.com/a/answer/6197508?hl=en

It alerts if you enter your google password anywhere but the real google sign in page.

Re: Our Copyfish extension was stolen and adware-infested

#65

A similar attack happened on another Chrome extension last month (Social Fixer) with over 190k installs. In fact, judging by the exploit code, I would guess the same author, as the Social Fixer attack had a very similar hashed package on Unpkg as well. In that scenario the author also didn't have 2FA enabled: https://www.facebook.com/socialfixer/posts/10155117415829342 I feel like Google should take the next step of…

> Google should take the next step of requiring all extension developers to enable 2FA before being able to post an extension.

Best comment here

Re: Our Copyfish extension was stolen and adware-infested

#66
This is the second extension that I use on chrome that has been hijacked.

The first was live http headers [0]

I have never had this experience on Firefox.

Is it simply a matter of Chrome being a bigger target?

[0] https://www.webmasterworld.com/webmaster/4829365.htm

Re: Our Copyfish extension was stolen and adware-infested

#67

This is the second extension that I use on chrome that has been hijacked. The first was live http headers [0] I have never had this experience on Firefox. Is it simply a matter of Chrome being a bigger target? [0] https://www.webmasterworld.com/webmaster/4829365.htm

The Great Suspender Chrome extension was also phished

https://github.com/deanoemcke/thegreatsuspender/issues/512

Re: Our Copyfish extension was stolen and adware-infested

#68
post #10

> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…

I find it strange the team member clicked on the link. For such high value accounts, always use google or type in the URL. Why would you click?

And worst of all, it was a bit.ly link they clicked.

Re: Our Copyfish extension was stolen and adware-infested

#69

Earlier quoted context omitted.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

> The only real defense is to glance at the url bar every time you're about to enter your password. With i18n not even that: https://www.theguardian.com/technology/2017/apr/19/phishing-... Benign POC: https://www.xn--80ak6aa92e.com/ (open it and it'll look like a normal "l" in the url box)

[deleted]

Re: Our Copyfish extension was stolen and adware-infested

#70
post #61

Earlier quoted context omitted.

This actually isn't true. A website like https://www.xn--80ak6aa92e.com/ won't show up as apple.com. Browsers don't allow Unicode rendering in the URL bar. Maybe IE is affected though. I haven't tested every browser. But it's a known security concern.

Sorry to tell you, does show up as apple.com in my browser. Chrome 52.0.2743.82-1 on Arch x86_64.

That version of Chrome is over a year old.
Post reply on HN