Kurt Got Got
fly.io
Kurt Got Got
1–10 of 256 posts
Re: Kurt Got Got
#2[dead]
Re: Kurt Got Got
#3I'm always glad to see when companies, developers and CEOs make a heartfelt and humanistic mae culpa.
We would like to think that we're the smart ones and above such low level types of exploits, but the reality is that they can catch us at any moment on a good or bad day.
Good write up
Re: Kurt Got Got
#4Great writeup, but also gotta say that’s some excellent phishing
Re: Kurt Got Got
#5Great writeup, but also gotta say that’s some excellent phishing
This exact phish has been going around lately and we're not the only ones who got bit. But we didn't know that before it happened.
Re: Kurt Got Got
#6[deleted]
Re: Kurt Got Got
#7I want to say again that the key thing in this post is that anything "serious" at Fly.io couldn't have gotten phished: your SSO login won't work if you don't have mandatory phish-resistant 2FA set up for it. What went wrong here is that Twitter wasn't behind that perimeter, because, well, we have trouble taking Twitter seriously.
We shouldn't have, and we do take it seriously now.
Re: Kurt Got Got
#8Ever since I almost got phished (wasn't looking closely enough at the domain to notice a little stress mark over the "s" in the domain name, thankfully I was using a hardware wallet that prevented the attack entirely), I realized that anyone can get phished. They just rely on you being busy, or out, or tired, and just not checking closely enough.
Use passkeys for everything, like Thomas says.
Re: Kurt Got Got
#9... could we get webauthn / yubikeys prioritized for fly? afaik (don't want to disable 2fa to find out), it only supports totp.
For everyone reading though, you should try fly. Unaffiliated except for being a happy customer. 50 lines of toml is so so much better than 1k+ lines of cloudformation.
Re: Kurt Got Got
#10This is why properly working password managers are important, and why as a web site operator you should make sure to not break them. My password not auto-filling on a web site is a sufficient red flag to immediately become very watchful.
Code-based 2FA, on the other hand, is completely useless against phishing. If I'm logging in, I'm logging in, and you're getting my 2FA code (regardless of whether it's coming from an SMS or an app).