Live data from Hacker News

Kurt Got Got

fly.io

101–110 of 256 posts

Re: Kurt Got Got

#101
post #95

Earlier quoted context omitted.

I think you'll be led astray thinking this is CEO-specific. The whole theory of phishing, and especially targeted phishing, is to present a scenario that tricks the user into ignoring the red flags. Usually, this is an urgent call to action that something negative will happen, coupled with a tie-in to something that seems legit. In this case, it was referencing a real post that the company had made. A parallel exampl…

I razz CEOs in jest, but my point is: This is an example of a good phishing attempt? ChatGPT could surely find and fix most of the red flags I called out. Perhaps the red flags ensure they don't phish more people than they can productively exploit.

There are certainly phishing attempts that are pixel perfect, but I'd say way more energy tends to go into making phishing websites perfect. The goal of the email is to flip people into action as quickly as possible with as little validation.

Re: Kurt Got Got

#103

This is why properly working password managers are important, and why as a web site operator you should make sure to not break them. My password not auto-filling on a web site is a sufficient red flag to immediately become very watchful. Code-based 2FA, on the other hand, is completely useless against phishing. If I'm logging in, I'm logging in, and you're getting my 2FA code (regardless of whether it's coming from a…

Turn off autofill, it is exploited by modern attacks including tapjacking

Re: Kurt Got Got

#104
post #77

Earlier quoted context omitted.

You're right. The point is that hotkey makes me think and observe more. Again, I don't have to remember if the site previous worked with autofill, or not.

Sure. Except this is a story about the user manually copying the credential into a phishing site after the password manager didn’t fill it in. Whether that’s via a hotkey or not seems totally irrelevant.

It doesn't seem irrelevant to me at all. Security these days isn't just one action, it is a multitude of actions and steps and thought processes.

By removing the expectation that my password manager is going to autofill something, I'm now making the conscious decision to always try to fill it myself.

This makes me think more about what I'm doing, and prevents me from making nearly as many mistakes. I don't let my guard down to let the tools do all the work for me. I have to think: ok, I'll autofill things now, realize that it isn't working, and then look more closely at why it wasn't working as I expected.

I won't just blindly copy/paste my credentials into the site because whoops, I think it might have worked previously.

Re: Kurt Got Got

#105
post #3

I'm always glad to see when companies, developers and CEOs make a heartfelt and humanistic mae culpa. We would like to think that we're the smart ones and above such low level types of exploits, but the reality is that they can catch us at any moment on a good or bad day. Good write up

>heartfelt and humanistic mae culpa

They literally admit they pay a Zoomer to make memes for Twitter. I think you are falling for the PR.

Re: Kurt Got Got

#106

When we did annual pen testing audits for my last company, the security audit company always offered to do phishing or social engineering attacks, but advised against it because they said it worked every single time. One of the most memorable things they shared is they'd throw USB sticks in the parking lot of the company they were pentesting and somebody would always put the thing into a workstation to see what as on…

The stray USB stick is how Stuxnet allegedly got deployed. Tbh I doubt that works in this day and age.

It does work.

Re: Kurt Got Got

#108
if anyone @ x.com infosec is here, my buddy got her account phished / there is someone in CS selling creds. Then it was used to pump a crypto scam and she has been trying for months to get it sorted. She's had the account for 16 plus years, it's surprising it's this hard to fix.

It's x.com/leighleighsf, we've tried every channel but for filing a small claims lawsuit in Texas to get her account back.

Re: Kurt Got Got

#109

This is why properly working password managers are important, and why as a web site operator you should make sure to not break them. My password not auto-filling on a web site is a sufficient red flag to immediately become very watchful. Code-based 2FA, on the other hand, is completely useless against phishing. If I'm logging in, I'm logging in, and you're getting my 2FA code (regardless of whether it's coming from a…

the creator of https://haveibeenpwned.com got phished once (no kidding), and he uses a password manager.

Re: Kurt Got Got

#110
post #35
post #19

Earlier quoted context omitted.

They prevent you from being one of these, and copy pasting the password from password manager into the wrong input field. Something that still happens often with many websites not properly auto-filling from password managers. > They just rely on you being busy, or out, or tired, and just not checking closely enough

If you are "copy-pasting" you are not using your password manager correctly.

Password managers rarely are able to autofill 100% of the time. Autofill breaking is not a very strong indicator of a phishing attempt, people are used to manually filling the password in sometimes for totally legit sites.
Post reply on HN