Live data from Hacker News

Kurt Got Got

fly.io

61–70 of 256 posts

Re: Kurt Got Got

#62
post #36

Earlier quoted context omitted.

That happened to me as well, I put it down to "fucking password manager, it's broken again". For example, BitWarden has spent the past month refusing to auto fill fields for me. Bugs are really not uncommon at all, I'd think my password manager is broken before I thought I'm getting phished (which is exactly how they get you).

Yeah i could totally see how someone in a bind working off of phone could get p0wned like that

For me it wasn't even a phone, it was on the desktop, I'm just so used to everything being buggy that it didn't trigger any alarms for me.

Luckily the only things I don't use passkeys or hardware keys for are things I don't care about, so I can't even remember what was phished. It goes to show, though, that that's what saved me, not the password manager, not my strong password, nothing.

Re: Kurt Got Got

#63
post #54

Earlier quoted context omitted.

Precisely. 1Password's browser integration would have noticed a domain mismatch and refused to autofill the password -- but in a panic, Kurt apparently opened 1Password and then copied/pasted the credentials manually.

Which is why a properly working password manager is not a strong defense against phishing.

Correct. The moral of the story is that hardware MFA and/or passkeys are a necessity in today's world. An infinitely complex password and 2FA are no match for attacks that leverage human psychology.

Re: Kurt Got Got

#64
post #30

This is why properly working password managers are important, and why as a web site operator you should make sure to not break them. My password not auto-filling on a web site is a sufficient red flag to immediately become very watchful. Code-based 2FA, on the other hand, is completely useless against phishing. If I'm logging in, I'm logging in, and you're getting my 2FA code (regardless of whether it's coming from a…

How does this square with the fact that the tech savvy person in the post was phished despite using a password manager.

[deleted]

Re: Kurt Got Got

#65
post #30

Earlier quoted context omitted.

How does this square with the fact that the tech savvy person in the post was phished despite using a password manager.

Precisely. 1Password's browser integration would have noticed a domain mismatch and refused to autofill the password -- but in a panic, Kurt apparently opened 1Password and then copied/pasted the credentials manually.

This is how they got my Steam account credentials, although I realized the stupid shit I did the second I clicked submit form, and reset my password to random 32 characters using bitwarden. Me! Someone who is deeply technical AND paranoid.

The key here is the hacker must create the most incisive, scary email that will short circuit your higher brain functions and get you to log in.

I should have realized the fact that bitwarden did not autofill and take that as a sign.

Re: Kurt Got Got

#66

Earlier quoted context omitted.

This is exactly why I turned off auto enter.

No, that's the opposite of the moral of that story. If the person you responded to had listened to the fact that the auto-enter didn't auto-enter, they wouldn't have been at any risk. Likewise in the article, the problem was that the CEO copy-pasted the password into the phishing page's password field, NOT that the auto-enter prompted him to do so.

As I mention below: Autofill doesn't always work for every site. So, now you're having to store in your mind where it works and where it doesn't. By disabling it, it forces you to go the extra step (command-shift-L) every time.

Re: Kurt Got Got

#67
post #59
post #48

Earlier quoted context omitted.

I think you mean Kurt.

You’re right - I flagged on Thomas’s name in the signature and because I’ve seen him around here, well, forever, but Kurt is also extremely savvy.

No he's not! He got taken by this dumb phishing thing!

Re: Kurt Got Got

#68
post #35
post #19

Earlier quoted context omitted.

They prevent you from being one of these, and copy pasting the password from password manager into the wrong input field. Something that still happens often with many websites not properly auto-filling from password managers. > They just rely on you being busy, or out, or tired, and just not checking closely enough

If you are "copy-pasting" you are not using your password manager correctly.

If only everyone did everything perfectly all the time, we wouldn't have any issues!

Re: Kurt Got Got

#69
post #33

Earlier quoted context omitted.

Isn’t turning off auto enter exacerbating the problem? The avenue for catching this is that the password manager’s autofill won’t work on the phishing site, and the user could notice that and catch that it’s a malicious domain

Autofill doesn't always work for every site. So, now you're having to store in your mind where it works and where it doesn't. By disabling it, it forces you to go the extra step (command-shift-L) every time.

Autofill and the hotkey use the same mechanism, and neither is going to work on a phishing site.

Re: Kurt Got Got

#70
Fly has consistently surprised me at how late they have been to doing the "standard company" stuff. Their sort of lack of support engineering teams for a while affected me way more though.

You gotta take the Legos away from the CEO! Being CEO means you stop doing the other stuff! Sorry!

And yes they have their silly disclaimer on their blog, but this is Yet Another "oh lol we made a whoopsie" tone that they've taken in the past several times for "real" issues. My favorite being "we did a thing, you should have read the forums where we posted about it, but clearly some of you didn't". You have my e-mail address!

Please.... please... get real comms. I'm tired of the "oh lol we're just doing shit" vibes from the only place I can _barely_ recommend as an alternative to Heroku. I don't need the cuteness. And 60% of that is because one of your main competitors has a totally unsearchable name.

Still using fly, just annoyed.

Post reply on HN