5 ms·
No, actually the article claimed the opposite: the attack was likely NOT credential stuffing..
by HenriNext 7y ago
No, actually the article claimed the opposite: the attack was likely NOT credential stuffing..
- qw3rty01 7y agoAfter reading the article, it's pretty clear that it was credential stuffing and that the writer didn't take the time to understand how it worked. Not sure what security experts they talked to, but credential stuffing absolutely can get all the information described, and the whole part about wifi connected devices is completely unrelated.
- HenriNext 7y agoI'm not making any guesses what actually happened. Just stating that you misrepresented what the article actually said when you wrote "the attack is called credential stuffing". Your sentence gives impression that the article would have said it, but the article made a point for the opposite.
- qw3rty01 7y agoThe Amazon spokesperson directly said it was credential stuffing--the article was trying to argue that it was more than that in an extremely misleading way.
- HenriNext 7y agoYou may be totally right and it was credential stuffing and the article may have been wrong, misleading, incompetent and stupid. Nonetheless, you misrepresented what the article actually said -- the article raised both, the possibility credential stuffing (implied by Amazon spokesperson), and doubt about it (unspecified security expert, WiFi attacks).
- qw3rty01 7y agoCalling out an article for being misleading is not the same as misrepresenting it.
- HenriNext 7y agoYes they are different, and you did both: called it out for being misleading, and simultaneously misrepresented what it actually said (I've already detailed the reasons above, and others have quoted them verbatim to you). The best before date of this conversation has clearly expired, so let's just stop here.
- geofft 7y agoIt's in Amazon's interest to argue that it wasn't a failing on their part.
- caf 7y agoI mean, being this susceptible to credential stuffing is a failing on their part, too.
- Pfhreak 7y ago> Not sure what security experts they talked to https://www.eff.org/about/staff/cooper-quintin https://www.eff.org/about/staff/cooper-quintin
- qw3rty01 7y agoThe article implied he wasn't the only one they talked with. There isn't anything he said that was explicitly incorrect (unlike some of the other unnamed security researchers), but he must not have much experience with credential stuffing incidents given his responses.
- sp332 7y agoAnd here is his take on it. https://twitter.com/cooperq/status/1207780461834977281 https://twitter.com/cooperq/status/1207780461834977281
- qw3rty01 7y agoI really wish this was included in the article, his conclusion makes a lot more sense in that context (though I still disagree with it).
- 55555 7y agoHis take is a result of him trying not to completely let go of the story he's already decided is significant. There is no story. There isn't really a great way to defend against credential stuffing attacks when the adversary has access to a huge residential proxy network and you don't want to greatly inconvenience your users. All major US banks are pretty vulnerable to credential stuffing attacks. If banks aren't going to defend against it, Ring isn't.