Live data from Hacker News

Our Copyfish extension was stolen and adware-infested

a9t9.com

71–80 of 217 posts

Re: Our Copyfish extension was stolen and adware-infested

#71
post #67

This is the second extension that I use on chrome that has been hijacked. The first was live http headers [0] I have never had this experience on Firefox. Is it simply a matter of Chrome being a bigger target? [0] https://www.webmasterworld.com/webmaster/4829365.htm

The Great Suspender Chrome extension was also phished https://github.com/deanoemcke/thegreatsuspender/issues/512

but apparently non-maliciously

Re: Our Copyfish extension was stolen and adware-infested

#72

Of course it's a phishing attack. Why would Google send you a bit.ly link to your own Google account?

"Note that the bitly link was not directly visible in the phishing email, as it was an HTML-email. That is another lesson learned: Back to standard, text-based email as the default."

I always look at the mouse over url. And check the URL in the address bar. And rely on the password manager in the browser. And sometimes login in a new tab, then go back and reload the link.

Re: Our Copyfish extension was stolen and adware-infested

#73
post #61

Earlier quoted context omitted.

This actually isn't true. A website like https://www.xn--80ak6aa92e.com/ won't show up as apple.com. Browsers don't allow Unicode rendering in the URL bar. Maybe IE is affected though. I haven't tested every browser. But it's a known security concern.

Sorry to tell you, does show up as apple.com in my browser. Chrome 52.0.2743.82-1 on Arch x86_64.

[deleted]

Re: Our Copyfish extension was stolen and adware-infested

#74

Earlier quoted context omitted.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

>> The only real defense is to glance at the url bar every time you're about to enter your password With Google specifically, the worst part is you really do have to look at the URL every single time you go to enter your password. And by that I mean that if you land on the login page, verify the URL, enter your password, submit, and get the error page saying you got the password wrong... you must check the URL again…

U2F is a second factor which can't be easily phished. If you are using a service which supports U2F and care a minimum about being secure, enabling it is the least you should do.

Re: Our Copyfish extension was stolen and adware-infested

#76

Earlier quoted context omitted.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

Lastpass will tell you whether it recognizes the site when you go to fill in the password (yes, I use it despite the scary stuff, I know I probably should switch to OnePassword). Do other password managers not do that? Just curious, not trying to engage the bigger question of whether getting phished is the user's fault.

Take a look at lesspass

Re: Our Copyfish extension was stolen and adware-infested

#77
post #71
post #67

Earlier quoted context omitted.

The Great Suspender Chrome extension was also phished https://github.com/deanoemcke/thegreatsuspender/issues/512

but apparently non-maliciously

What do you mean?

I thought the attacker stole the account maliciously, but hadn't quite gotten around to inserting the malware by the time it was taken back.

Re: Our Copyfish extension was stolen and adware-infested

#78
post #10

> “Click here to read more details” the email said. The click opened the “Google” password dialog, and the unlucky team member entered the password for our developer account. This looked all legit to the team member, so we did not notice the pishing attack as such at this point. Pishing for Chrome extensions was simply not on our radar screen. First, it is excellent that you disclosed the issue. Second, based upon th…

Incorrect. They literally declared "we were phished", in plain words, describing how they were phished and the resulting attack. To say this does not "accept responsibility" is bullshit. You don't get to light the torches and grab the pitchforks to go chase some stranger who exposed you to vulnerability. They are human, they failed, and they're dealing it with professionally.

I'm assuming from your tone of "I demand his head" that you were running the compromised extension, and wish to extract your pound of flesh from the person who compromised you. (EDIT: If not, what's your beef with them? Are you a competitor? Please explain!) This, too, is wrong. And here's why we don't play the blame game when it comes to human failures:

You chose to run a Chrome extension, from an untrusted source, with only machine automation vetting its contents and auto-update ensuring that you get the latest attack. Of course you got compromised. What else did you expect? How could you place ultimate trust for all content in your browser in the hands of an OCR extension?! What on earth could compel you to accept such a ridiculous risk in exchange for this?

Everyone's human, you included. They clearly stated and accepted responsibility for the incident. Now you need to stand up and accept responsibility for running unvetted code in your browser. (EDIT: Yes, it's machine-vetted. How's that working out for you?)

There's more than enough blame to ensure you get an equal portion. Being human is bad enough without people coming to destroy you because they'd rather not confront their own failures of judgement. Get over your immature desire to get your vengeance for being compromised and build a better approach to your own personal security.

Re: Our Copyfish extension was stolen and adware-infested

#79

Earlier quoted context omitted.

"Note that the bitly link was not directly visible in the phishing email, as it was an HTML-email. That is another lesson learned: Back to standard, text-based email as the default."

I always look at the mouse over url. And check the URL in the address bar. And rely on the password manager in the browser. And sometimes login in a new tab, then go back and reload the link.

bit.ly addresses don't keep their URL in the address bar (Eg. http://bit.ly/19y8wyr for HN), so it's possible you might not notice it once you've clicked, depending on how realistic the malicious target URL was.

Re: Our Copyfish extension was stolen and adware-infested

#80

Earlier quoted context omitted.

It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…

That's a good habit, but a good tool to help you avoid getting phished is https://support.google.com/a/answer/6197508?hl=en It alerts if you enter your google password anywhere but the real google sign in page.

Ah, the delightful irony. Install a chrome extension to warn you if you get owned by a chrome extension.
Post reply on HN