3 ms·
from the quick read, it looks like a spear phishing attack at the root of it. --- According to the report by the FBI and DHS, the hackers involved in the Russi
by smaddali 10y ago
from the quick read, it looks like a spear phishing attack at the root of it.
---
According to the report by the FBI and DHS, the hackers involved in the Russian operation used fraudulent emails that tricked their recipients into revealing passwords.
---
This incident should be investigated thoroughly and serious defenses should be put in place. Destabilizing the electric grid like the Kiev incident shouldn't be allowed.
- drzaiusapelord 10y agoYeah I'm surprised 2FA isn't the norm with organizations that work with the government or control infrastructure. The idea of just using a password is fairly idiotic. They're too easy speared and cracked.
- eli 10y agoWhat's preventing the bad guys from phishing a 2FA token on their fake login page too?
- jacalata 10y agoIt should make it harder because you have to run the attack based on the user interaction timing, you can't just capture and hold credentials for later.
- eli 10y agoNo doubt, but that's hardly an obstacle for an even moderately sophisticated attacker. I don't know what the magic bullet answer to phishing is, but this ain't it.
- Spooky23 10y agoUsually 2FA is only at the perimeter where you have legacy or embedded systems. There's always a way in.