3 ms·
Just for the heck of it I created a test account with their password manager with a few honeypot accounts on a VPS server. Within 2 hours one of the "honeypot"
by g2294994 8y ago
Just for the heck of it I created a test account with their password manager with a few honeypot accounts on a VPS server.
Within 2 hours one of the "honeypot" SSH accounts I put in my password manager was accessed with the creds I provided in the password manager. Now I understand there is internet wide scanning but a succesfull login with a random 12 character username and password I had in my password safe is very unlikely to be a random bot account.
Tomorrow I might have a bit more time to throw a few more honeypot accounts in there and see if they attempt to login.
For the time being I would highly discourage anyone store their passwords there.
(using a random throwaway account for obvious reasons, I don't want any retaliation against my startup on my main account from these guys.)
- PirateBay 8y agoReally sickening that this sort of stuff is going to inevitably be aggressivly marketed to unsuspecting people. Tunnelbear(same company) is shilled extremely hard by youtube tech content creators who should know better, to people who trust them.
- frio 8y agoMost analysis I can find (admittedly, I've only tried a few variations of the search on Google) says TunnelBear is a relatively decent paid VPN. Are you implying TunnelBear, the company, shouldn't be trusted? If not, why not?
- computerfriend 8y agoOne reason would be that they allegedly steal passwords entrusted to their password manager.
- gravelc 8y agoThat's quite astonishing. Have you done the same sort of check with other password managers like LastPass? Really hope this isn't widespread.
- g2294994 8y agoThis is not a widespread issue by any means. All the reputable online password managers that I have tested so far in the last several years haven't attempted to access any of the honeypot accounts. I'm a pentester by day so this is more of a side hobby I do in my off time.
- nathanaldensr 8y agoCan anyone else verify these observations? Talk about honeypots... sheesh.
- heyoni 8y agoSomeone needs to replicate this because it wouldn't make any sense for them to make use of them on day one rather than wait and accumulate. Since you're anonymous anyways, why not just tell us what you know? Are they breached or is the platform itself some sort of trap?
- g2294994 8y agoThis type of behavior one would expect from a sketchy site so these early test results are somewhat surprising to be honest. I will be doing further testing in the next few weeks by throwing a few more honeypot accounts in different accounts created under different ip's. What I'm curious about is whether they do a bulk search for a keyword such as "SSH" across their database or do they target accounts from a certain geographic location and not touch others. Another possible theory is that the site has a weakness and has been breached but they are just not aware of it. At this point it's a bit too early too tell though. I encourage other people to test this on their end as well. It's actually very easy to do, spin up a vm image in the cloud, throw some test creds and see who falls for the bait. I keep a simple spreadsheet with unique usernames in one column and the service I stored those honeypot accounts in the next column. If one of those are accessed then I know for certain which services not to trust.
- heyoni 8y agoOh man, I thought you worked for remembear and were outing them! This makes way more sense. And yea, that's really clever, but you really think they'll still be trying this after posting about it publicly?