5 ms·
The beginning of the story is missing. PZ clicked on the link in the email because it was "received [...] from a familiar mailing list". Did PZ trust a mailing
by nmc 10y ago
The beginning of the story is missing. PZ clicked on the link in the email because it was "received [...] from a familiar mailing list".
Did PZ trust a mailing list where anyone could post? Or did the attackers spoof the "from" field? The former may have been prevented by employee training, the latter by SPF or similar technologies.
- phn 10y agoOr it could come from an already infected account, which might make the e-mail even less suspicious.
- nmc 10y agoYes but this would just mean an even bigger part of the story is missing — how that one got compromised.
- pauldancstep 10y agoHi, I'm the author of that blog post. The backstory is that, indeed, the "familiar mailing list" had been compromised; the attack was conveyed to us in much the same way as we passed it on to others.
- emodendroket 10y agoI mean, I don't think the argument at any point is that it couldn't have possibly been prevented or that nobody made a mistake in this story.
- tomjen3 10y agoSharing links is so common that if you want to punish users for that you can't run your business anymore. But yeah they shouldn't login on sites that the password isn't auto completed for.
- wichert 10y agoIn my experience if you use multiple Google accounts you get login prompts all the time: half the time the Google Doc/Drive link requires me to switch to another account, and occasionally asking for password confirmation as well.