Live data from Hacker News

On Getting Hacked

ahmeto.com

51–60 of 77 posts

Re: On Getting Hacked

#51
post #16
post #15

Earlier quoted context omitted.

It’s also an issue that extensions like 1Password are _too_ URL-aware, until recently it tried to use heuristics and ignore subdomains for matching credentials. This meant that we used to get a list of almost a hundred options when logging into our AWS infrastructure. No matter which actual domain used. Someone could have used this vulnerability as part of a phishing campaign.

Haha and Bitwarden is url aware but not enough. I work in a company where I have two okta accounts (because hey, why not) on two .okta.com subdomains. Bitwarden _randomly_ messes up the two subdomains and most of the times (but not always, which seems strange actually), it fills the form with the wrong password. I don’t know why. I know that there is an option to make it stricter on domain matching but you can’t conf…

Every browser-based bitwarden client I have used have the option to choose the autofill option on single items as well as the global default. Find the login item, click edit, scroll to autofill options, where each URI is listed with a gear icon next to it. Click the gear and select the appropriate match type.

For the absolute majority of use cases, "host" should be the default, but i have found uses for both "base domain" and "regular expression" in some special cases.

Normal browser extension Bitwarden Ctrl-Shift-L autofill defaults to the most recently used entry when there are multiple matches, afaik.

Re: On Getting Hacked

#52
post #50

Great article on reminding the risks of browser extensions. They literally have access to everything within the browser window, from usernames and passwords to bank account details. Funnily I always tempted by extensions that offer dark more for webpages but never dared to install one. I do use extensions, but only if they are from well known, respected organisations. The author was lucky that it was only few comprom…

I'm relatively happy that I got away with a couple of suspended social media accounts and a lesson that I can share, which will improve my awareness. Would've been a totally different story had it reached more serious services like a bank account or iCloud.

Re: On Getting Hacked

#53
post #9

Had a close call: Apparently it's possible to bypass 2FA and do a password reset of a Google account without email access, if the account owner doesn't abort it within 30 days. I confirmed that it works by "pwning myself" afterwards. So keep an eye on your old Gmail inbox if it matters.

Apparently?

i.e -> fake news.

Re: On Getting Hacked

#54
post #37

Earlier quoted context omitted.

Using SMS 2FA has been explicitly deprecated for years. It’s insecure for this and a million other reasons. TOTP is also trivially phishable. I still have my sense of smugness because I use SOTA 2fa.

I wish banks would get this memo. Not only is one of my banks enforcing a maximum password length of 6 NUMBERS (no letters/special characters allowed), but also that high-value transfers are only confirmed via SMS 2FA, even though their own banking app also have a separate 2FA thing that doesn't go through SMS, but it's only used for "low-value" actions...

Name and shame

Tangerine (formally ING Direct) in Canada only has 6-digit PINs and SMS 2FA

TD Canada Trust only supports SMS 2FA

PC Financial only supports SMS 2FA

Re: On Getting Hacked

#56
post #9

Had a close call: Apparently it's possible to bypass 2FA and do a password reset of a Google account without email access, if the account owner doesn't abort it within 30 days. I confirmed that it works by "pwning myself" afterwards. So keep an eye on your old Gmail inbox if it matters.

Apparently? i.e -> fake news.

No.

First-hand account.

Re: On Getting Hacked

#58
post #48
post #37

Earlier quoted context omitted.

Using SMS 2FA has been explicitly deprecated for years. It’s insecure for this and a million other reasons. TOTP is also trivially phishable. I still have my sense of smugness because I use SOTA 2fa.

TOTP is not SOTA 2FA. WebAuthn is SOTA 2FA. TOTP can be phished. WebAuthn cannot.

[deleted]

Re: On Getting Hacked

#59
post #49

> TikTok deemed I should not have access to my account ever again, and X (formerly Twitter) is delaying a response to my appeal to the suspension, but I have not much hope; I reckon it's gone for good. I may have lost all the personal contacts and content from there, but on the bright side, that has taught and made me see some other things, besides the importance of being a little smarter to not blindly install exten…

Not sure why OSS is mentioned here, should just say "software". And it's always been like this (be careful).

Re: On Getting Hacked

#60
The first time I got "hacked" was around 1995.

Someone I trusted at the time sent me a modified Legend of The Red Dragon bbs door game expansion/mod that del C:\

Learned a lot that day.

Post reply on HN