4 ms·
They don't see the potential impact of associating a particular username from a jobs website with an email address? I would be concerned about more targeted ph
by TeHCrAzY 15y ago
They don't see the potential impact of associating a particular username from a jobs website with an email address?
I would be concerned about more targeted phishing attacks: I tend towards using my real name as my username on job websites, and given a list of usernames and emails, I'm very sure you could produce some more believable phishing emails than regularly received.
Edit: Thinking more on this, it would be reasonable in any of these email + username exposures to simply apply a filter of common names, and then use them in a more legitimate looking email. I don't see much of this in my spam (my email address is firstnamelastname@domain.com, and my first name is common), so I would take a stab and say that perhaps the number of people likely to fall for this would not significantly increase with improvement in the quality of the initial email.
- d0ne 15y agoThat is exactly what one should worry about.
- biot 15y agoFrom: security@washingtonpost.com To: [your email] Subject: Washington Post Vulnerability Update Dear [name], Our initial investigation revealed that an unauthorized third party managed to retrieve the list of user IDs and email addresses associated with Washington Post Jobs accounts, of which yours was one. Our security team has performed a more thorough audit of the attack which resulted in the exposure of your information and has determined that the unauthorized third party was also able to gain access to encrypted passwords. Because the passwords were encrypted, it is unlikely that the attackers will be able to access your Jobs account. However, due to the very small chance that this unauthorized third party may be able to decrypt your password, we are requiring every Jobs account holder to change their password within the next 48 hours. Failure to change your password will result in your account being permanently locked out. To further enhance the security of our Jobs site, you will need to specify your existing password as well as your new password. Your new password must be at least eight characters long and have one or more upper case letters, one or more lower case letters, and one or more numbers or symbols. Please change your password at the following URL: [link to phishing site that looks like Washington Post's Jobs site with a realistic password change form that will dutifully accept your email and current password and enforce the new password requirement for good appearances] Sincerely, Washington Post Jobs Customer Service
- tptacek 15y agoAh. SQLI.
- TeMPOraL 15y agoWow. That looks legitimate. we are requiring every Jobs account holder to change their password within the next 48 hours. Failure to change your password will result in your account being permanently locked out. That's the bit that got me thinking, but more on the lines of "WTF?!" than recognizing this as a phishing attempt.
- biot 15y agoI figure most people might think if changing the password is optional, why bother? That line provides timely motivation to do so immediately. On further thought, I'd also remove the part which mentions supplying the current password and just focus on the new password requirements. The form on the site would naturally ask for their current password.