How the Syrian Electronic Army Hacked The Onion
41–50 of 68 posts
Re: How the Syrian Electronic Army Hacked The Onion
#42Google requiring you to enter your password at random times for random things (e.g. to read a Google Groups message) seems like one contributing factor, since people treat those prompts as routine noise, and are less likely to investigate such a common occurrence too deeply.
Re: How the Syrian Electronic Army Hacked The Onion
#43Re: How the Syrian Electronic Army Hacked The Onion
#44I often think about creating a browser and email plugin/extension to help with this: - Look at all link tags. - If it looks like a URL (has a scheme at the beginning, or something which resembles a hostname, or a bunch of path or query parameters), inspect the actual link. - If they have different hosts, warn the user, and perhaps give them the option of just visiting what the contents of the link tag say (rather tha…
Re: How the Syrian Electronic Army Hacked The Onion
#45Earlier quoted context omitted.
I agree with this point. I retype my user information, even while logged in, at least a few times a week.
That's odd because I never do. I'm using two-factor and I only have to retype login information when that expires (approximately 30 days I believe.) Also, someone did phish my Google cookies and Google immediately shutdown my account and made me type in something from a text to reactivate my account. Overall I'm pretty happy with both of those circumstances.
Re: How the Syrian Electronic Army Hacked The Onion
#46One more reason to use 2FA on your Google Apps account.
One problem I have with the current 2FA on Google Apps is that there is no way to enforce 2FA for all users before everyone sets up their mobile device. If you've set the requirement for all to have 2FA, then new users can never log in. You're then left in this limbo of some with/some without 2FA, and unless you actively pursue those without it setup, you can never change that system wide setting in the control panel…
Re: How the Syrian Electronic Army Hacked The Onion
#47One more reason to use 2FA on your Google Apps account.
Re: How the Syrian Electronic Army Hacked The Onion
#48Yet another reason to use a password plugin like 1Password or Keepass or whatever: because they memorize password-per-domain, they do not attempt to fill in a password when the domain is merely similar to a known domain.
Re: How the Syrian Electronic Army Hacked The Onion
#49This, of course, is an artefact of the well-known, old problem of your email being the single point of failure for your entire online identity.
Google might be able to do something to help here: Surely, they can detect with high reliability if a given email contains a password reset link, and trigger an extra challenge. I'm not sure what it should be, as obviously the account password isn't going to cut it. It could really just be a very short PIN-style code for opening "sensitive" email.
Re: How the Syrian Electronic Army Hacked The Onion
#50Earlier quoted context omitted.
2FA is great, but it wouldn't save you here if you ask it to remember you for 30 days.
It would have stopped someone from using a phished GApps credential from logging in to Google using it, though. It sounds like one prong of the attack was to gain access to one employee's email, then use that account to send phishing emails to other employees. 2FA would have stopped that.
1- get target to enter google credentials
2- log into target's account using those credentials with a proxy/controlled IP that shows up nearby in geoip DBs
3- display a credible message, asking for 2factor code (something something DHCP something something more buzzwords - dummy mode on)
Any reason this wouldn't work?