Live data from Hacker News

Kurt Got Got

fly.io

71–80 of 256 posts

Re: Kurt Got Got

#71
post #61
post #55

Earlier quoted context omitted.

It would help if they mentioned his name anywhere in the post, title, or subtitle.

Yeah, that was definitely a pebkac on my part.

It's ok, I just couldn't pass up a good opportunity for snark!

Re: Kurt Got Got

#72
post #54

Earlier quoted context omitted.

Precisely. 1Password's browser integration would have noticed a domain mismatch and refused to autofill the password -- but in a panic, Kurt apparently opened 1Password and then copied/pasted the credentials manually.

Which is why a properly working password manager is not a strong defense against phishing.

It's a strong defense that this guy decided not to use

Re: Kurt Got Got

#73

Earlier quoted context omitted.

Precisely. 1Password's browser integration would have noticed a domain mismatch and refused to autofill the password -- but in a panic, Kurt apparently opened 1Password and then copied/pasted the credentials manually.

This is how they got my Steam account credentials, although I realized the stupid shit I did the second I clicked submit form, and reset my password to random 32 characters using bitwarden. Me! Someone who is deeply technical AND paranoid. The key here is the hacker must create the most incisive, scary email that will short circuit your higher brain functions and get you to log in. I should have realized the fact tha…

Same thing happened to me (not with Steam), but it's also the thought that "this could never happen to me" that leads you to assign an almost zero probability to the problem being a phishing attempt.

Re: Kurt Got Got

#74
post #69

Earlier quoted context omitted.

Autofill doesn't always work for every site. So, now you're having to store in your mind where it works and where it doesn't. By disabling it, it forces you to go the extra step (command-shift-L) every time.

Autofill and the hotkey use the same mechanism, and neither is going to work on a phishing site.

You're right. The point is that hotkey makes me think and observe more. Again, I don't have to remember if the site previous worked with autofill, or not.

Re: Kurt Got Got

#75
post #54

Earlier quoted context omitted.

Which is why a properly working password manager is not a strong defense against phishing.

It's a strong defense that this guy decided not to use

User security that doesn’t meet real users where they are is just nerd theatre.

Re: Kurt Got Got

#76
post #30

This is why properly working password managers are important, and why as a web site operator you should make sure to not break them. My password not auto-filling on a web site is a sufficient red flag to immediately become very watchful. Code-based 2FA, on the other hand, is completely useless against phishing. If I'm logging in, I'm logging in, and you're getting my 2FA code (regardless of whether it's coming from a…

How does this square with the fact that the tech savvy person in the post was phished despite using a password manager.

Because CEOs at startups are notorious for trying to problem solve aggressively by "just" doing the thing rather than throwing it at a person who _might_ have made the same mistake, but might be more primed to be confused as to why they are not logged into x dot com and why 1password's password prompt doesn't show up and why the passkey doesn't work or whatever.

It's always possible to have issues, of course, and to make mistakes. But there's a risk profile to this kind of stuff that doesn't align well with how certain people work. Yet those same people will jump on these to fix it up!

Re: Kurt Got Got

#77
post #69

Earlier quoted context omitted.

Autofill and the hotkey use the same mechanism, and neither is going to work on a phishing site.

You're right. The point is that hotkey makes me think and observe more. Again, I don't have to remember if the site previous worked with autofill, or not.

Sure. Except this is a story about the user manually copying the credential into a phishing site after the password manager didn’t fill it in.

Whether that’s via a hotkey or not seems totally irrelevant.

Re: Kurt Got Got

#79
post #43
post #33

Earlier quoted context omitted.

Isn’t turning off auto enter exacerbating the problem? The avenue for catching this is that the password manager’s autofill won’t work on the phishing site, and the user could notice that and catch that it’s a malicious domain

Yes. This is the problem with the "just use a password manager" answer to phishing-resistance. They can be a line of defense, situationally, but you have to have them configured just right, and if you're using phishing-resistant authentication you don't need that line of defense in the first place.

Isn't this backwards? If the autocomplete doesn't show up that's a flag that the password is going somewhere it doesn't belong. If you're always copy-pasting from a password manager then you're not getting that check "for free".

Obviously SSO-y stuff is _better_, but autofill seems important for helping to prevent this kind of scam. Doesn't prevent everything of course!

Re: Kurt Got Got

#80
post #70

Fly has consistently surprised me at how late they have been to doing the "standard company" stuff. Their sort of lack of support engineering teams for a while affected me way more though. You gotta take the Legos away from the CEO! Being CEO means you stop doing the other stuff! Sorry! And yes they have their silly disclaimer on their blog, but this is Yet Another "oh lol we made a whoopsie" tone that they've taken…

We've had an unusually large security team for the size of our company since 2021. I'm sorry if you don't like the way I communicate about it but I have no plans to change that. We take security extremely seriously. We just didn't take Twitter that seriously.

The "CEO" thing is just a running joke. Kurt's an engineer. Any of us could have been taken by this. I joke about this because I assume everybody gets the subtext, which is that anything you don't have behind phishing-resistant authentication is going to get phished. You apparently took it on the surface level, and believe I'm actually dunking on Kurt. No.

Post reply on HN