Live data from Hacker News

Our Copyfish extension was stolen and adware-infested

a9t9.com

141–150 of 217 posts

Re: Our Copyfish extension was stolen and adware-infested

#141

Earlier quoted context omitted.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

> The only real defense is to glance at the url bar every time you're about to enter your password. With i18n not even that: https://www.theguardian.com/technology/2017/apr/19/phishing-... Benign POC: https://www.xn--80ak6aa92e.com/ (open it and it'll look like a normal "l" in the url box)

Latest Chrome and Safari shows that as https://www.xn--80ak6aa92e.com, no puny code

Re: Our Copyfish extension was stolen and adware-infested

#143
post #14

Earlier quoted context omitted.

While I normally agree, I think it's important that they referred to the specific person without using blaming language. The team failed and screwed up because they had bad policies with their account. The individual team member who was holding the keys when the screw-up happened? Unlucky. Fix the process, not the people. It's good that they're not throwing the poor person under the bus.

Stating what happened is not blaming language. Characterizing the act as "unlucky" is excusing language, just as bad as blaming language. Assigning an error to mystical forces is unhelpful. Simply stating that the person entered the password into a phishing site is not blaming language, it is factual.

I would kindly ask that the person who has never made a mistake throw the first stone.

Re: Our Copyfish extension was stolen and adware-infested

#144

I guess this is as good a place as any to post that I noticed something similar had happened to [User-Agent Switcher for Google Chrome]( https://chrome.google.com/webstore/detail/user-agent-switche... ) and [Block Site]( https://chrome.google.com/webstore/detail/block-site/eiimnmi... ). The "report abuse" link on the page is useless. The former is very insidious in that it actually hides the malware in a .jpg file th…

Damn! I was using this all along!. Removed it immediately and checked the chrome store for an alternative, there's one from Google itself.

Re: Our Copyfish extension was stolen and adware-infested

#145
> Back to standard, text-based email as the default.

Yeah, but what will you do when your receive an HTML-only mail, or a mail with text/plain alternative saying "lol, get a better MUA", or a mail with text/plain alternative so mangled it can't be read without making your brain hurt?

All these are common occurrences in automatically sent e-mails these days.

Re: Our Copyfish extension was stolen and adware-infested

#146
post #145

> Back to standard, text-based email as the default. Yeah, but what will you do when your receive an HTML-only mail, or a mail with text/plain alternative saying "lol, get a better MUA", or a mail with text/plain alternative so mangled it can't be read without making your brain hurt? All these are common occurrences in automatically sent e-mails these days.

View the HTML mail, but with fancy rendering, images, all remote content, etc. disabled.

Thunderbird does this by default.

Re: Our Copyfish extension was stolen and adware-infested

#147

Earlier quoted context omitted.

Stating what happened is not blaming language. Characterizing the act as "unlucky" is excusing language, just as bad as blaming language. Assigning an error to mystical forces is unhelpful. Simply stating that the person entered the password into a phishing site is not blaming language, it is factual.

I would kindly ask that the person who has never made a mistake throw the first stone.

I'm with you, this entire thread has brought out the captain hindsight in everyone.

Re: Our Copyfish extension was stolen and adware-infested

#148

Earlier quoted context omitted.

More or less why I run a fairly minimal set of extensions. I was looking for a bulk downlowned about a week ago, and the only ones I found requested "Read data from all websites", which is a lot of trust to put in something I have limited ability to test/know if it is malicious. Side note: Chrome appears to have moved Extensions out of Settings since I last looked, and the "search settings" bar doesn't bring it up ei…

> I was looking for a bulk downlowned about a week ago, and the only ones I found requested "Read data from all websites", which is a lot of trust to put in something I have limited ability to test/know if it is malicious. AIUI that's a consequence of the Chrome extension security model. How could a bulk-downloader extension download files from arbitrary web sites without "Read[ing] data from all websites"? Compare t…

> AIUI that's a consequence of the Chrome extension security model. How could a bulk-downloader extension download files from arbitrary web sites without "Read[ing] data from all websites"?

What I was hoping for was something along the lines of " wants to access this page" (similar to the notification when a website tries to access your location) upon use. I've no idea if that's possible or not in the Chrome security model.

Re: Our Copyfish extension was stolen and adware-infested

#149

We should never have to read a title "disable immediately" by a developer. In a news article. That is not how this should be distributed, in case the original developer is the one distributing the news. Instead, Google should generate an emergency disable code that a developer can put into a simple web form from anywhere in the world, even if the developer has been locked out of every one of their accounts, which imm…

How would you handle exposed disable codes (say if a person who had access to it leaves the company)? There are presumably situations where revocation of the code would be needed, but that seems difficult to implement without also opening a window for the attacker to use:

* instant revocation -> attacker will just revoke the code * delayed revocation where the code remains usable for some period -> accidental exposure is irrecoverable

Maybe it's viable as an option (extension owner takes on the risk of properly managing the secret, knowing it can't be revoked easily).

Re: Our Copyfish extension was stolen and adware-infested

#150
post #145

> Back to standard, text-based email as the default. Yeah, but what will you do when your receive an HTML-only mail, or a mail with text/plain alternative saying "lol, get a better MUA", or a mail with text/plain alternative so mangled it can't be read without making your brain hurt? All these are common occurrences in automatically sent e-mails these days.

View the HTML mail, but with fancy rendering, images, all remote content, etc. disabled. Thunderbird does this by default.

> View the HTML mail

And that's exactly what phishers want you to do.

Post reply on HN