Live data from Hacker News

Kurt Got Got

fly.io

81–90 of 256 posts

Re: Kurt Got Got

#81
post #75

Earlier quoted context omitted.

User security that doesn’t meet real users where they are is just nerd theatre.

It works for me. I’m unconcerned if it works for anybody else.

It works for lots of people, until it doesn't. You may well fall victim to such a scheme someday.

Re: Kurt Got Got

#82
post #76
post #30

Earlier quoted context omitted.

How does this square with the fact that the tech savvy person in the post was phished despite using a password manager.

Because CEOs at startups are notorious for trying to problem solve aggressively by "just" doing the thing rather than throwing it at a person who _might_ have made the same mistake, but might be more primed to be confused as to why they are not logged into x dot com and why 1password's password prompt doesn't show up and why the passkey doesn't work or whatever. It's always possible to have issues, of course, and to…

It’s a bold move to typecast all CEOs as uniquely vulnerable to a problem that the evidence shows every single one of us is vulnerable to.

Blaming some attribute about user as why they fell for a phishing attempt is categorically misguided.

Re: Kurt Got Got

#83
post #30

This is why properly working password managers are important, and why as a web site operator you should make sure to not break them. My password not auto-filling on a web site is a sufficient red flag to immediately become very watchful. Code-based 2FA, on the other hand, is completely useless against phishing. If I'm logging in, I'm logging in, and you're getting my 2FA code (regardless of whether it's coming from a…

How does this square with the fact that the tech savvy person in the post was phished despite using a password manager.

The post calls this out:

> the 1Password browser plugin would have noticed that “members-x.com” wasn’t an “x.com” host.

But shared accounts are tricky here, like the post says it's not part of their IdP / SSO and can't be, so it has to be something different. Yes, they can and should use Passkeys and/or 1password browser integration, but if you only have a few shared accounts, that difference makes for a different workflow regardless.

Re: Kurt Got Got

#84
post #79
post #43

Earlier quoted context omitted.

Yes. This is the problem with the "just use a password manager" answer to phishing-resistance. They can be a line of defense, situationally, but you have to have them configured just right, and if you're using phishing-resistant authentication you don't need that line of defense in the first place.

Isn't this backwards? If the autocomplete doesn't show up that's a flag that the password is going somewhere it doesn't belong. If you're always copy-pasting from a password manager then you're not getting that check "for free". Obviously SSO-y stuff is _better_, but autofill seems important for helping to prevent this kind of scam. Doesn't prevent everything of course!

None of this password manager configuration stuff matters; we've just got Passkeys set up for the account now, which is what we should have done, but didn't, because we spent the last 2 years with one foot out the door on Twitter altogether.

Since this attack happened despite Kurt using 1Password, I'm really not all that receptive to the idea that 1Password is a good answer to this problem.

Re: Kurt Got Got

#85
post #84
post #79

Earlier quoted context omitted.

Isn't this backwards? If the autocomplete doesn't show up that's a flag that the password is going somewhere it doesn't belong. If you're always copy-pasting from a password manager then you're not getting that check "for free". Obviously SSO-y stuff is _better_, but autofill seems important for helping to prevent this kind of scam. Doesn't prevent everything of course!

None of this password manager configuration stuff matters; we've just got Passkeys set up for the account now, which is what we should have done, but didn't, because we spent the last 2 years with one foot out the door on Twitter altogether. Since this attack happened despite Kurt using 1Password, I'm really not all that receptive to the idea that 1Password is a good answer to this problem.

I guess I'm just saying "1Password with autofill" will help more than "1Password without autofill".

We can always make mistakes of course. And yeah, sometimes we just haven't done something.

Re: Kurt Got Got

#86

Earlier quoted context omitted.

It works for me. I’m unconcerned if it works for anybody else.

It works for lots of people, until it doesn't. You may well fall victim to such a scheme someday.

That’s almost guaranteed now that I made such a confident statement that it works for me.

Re: Kurt Got Got

#87
post #85
post #84

Earlier quoted context omitted.

None of this password manager configuration stuff matters; we've just got Passkeys set up for the account now, which is what we should have done, but didn't, because we spent the last 2 years with one foot out the door on Twitter altogether. Since this attack happened despite Kurt using 1Password, I'm really not all that receptive to the idea that 1Password is a good answer to this problem.

I guess I'm just saying "1Password with autofill" will help more than "1Password without autofill". We can always make mistakes of course. And yeah, sometimes we just haven't done something.

I'm saying: an intervention was required here, and that intervention was not changing how we use auto-fill. Doing that would be playing to lose.

Re: Kurt Got Got

#88
post #22

Earlier quoted context omitted.

This whole story is about us getting zapped because we relied on a good long password in a password manager!

So what happened exactly? Did Kurt enter his twitter password manually after clicking on that phishing link? Did he not get his sus detector going off after the password manager didn't suggest the password?

Unfortunately, this does not work. I see no end of banks, financial institutions, let alone random companies, who keep their authentication, for some reason, on different domain than main company, and sometimes they would have initial registration (which gets recorded in password manager) on one domain, and consequent logins on another, and sometimes it depends on how you arrived at the site, or which integration are you planning to use, etc. I wish there were a rule "one company - one auth domain" but it's just not true.

Example: Citi bank has citibankonline.com, citi.com, citidirect.com, citientertainment.com, etc. Would you be suspicious of a link to citibankdirect.com? Would you check the certificate for each link going there, and trace it down, or just assume Citi is up to their shenanigans again and paste the password manually? It's jungle out there.

Re: Kurt Got Got

#89

When we did annual pen testing audits for my last company, the security audit company always offered to do phishing or social engineering attacks, but advised against it because they said it worked every single time. One of the most memorable things they shared is they'd throw USB sticks in the parking lot of the company they were pentesting and somebody would always put the thing into a workstation to see what as on…

The stray USB stick is how Stuxnet allegedly got deployed. Tbh I doubt that works in this day and age.

What I heard about the Stuxnet attack was different from what you are saying:

The enrichment facility had an air-gapped network, and just like our air-gapped networks, they had security requirements that mandated continuous anti-virus definition updates. The AV updates were brought in on a USB thumb drive that had been infected, because it WASN'T air-gapped when the updates were loaded. Obviously their AV tools didn't detect Stuxnet, because it was a state-sponsored, targeted attack, and not in the AV definition database.

So they were a victim of their own security policies, which were very effectively exploited.

Re: Kurt Got Got

#90
I don't know the gullibility of the average tech CEO but this doesn't strike me as a very convincing phishing attempt.

* "We've received reports about the latest content" - weird copy

* "which doesn't meet X Terms of Service" - bad grammar lol

* "Important:Simply ..." - no spacing lol

* "Simply removing the content from your page doesn't help your case" - weird tone

* "We've opened a support portal for you " - weird copy

There should so many red flags here if you're a native english speaker.

There are some UX red flags as well, but I admit those are much less noticeable.

* Weird and inconsistent font size/weight

* Massive border radius on the twitter card image (lol)

* Gap sizes are weird/small

* Weird CTA

Post reply on HN