4 ms·
"had access to a support engineer’s laptop" is very vague, they could have: 1. some kind of remote access to the support engineer's session on that laptop
by warp 5y ago
"had access to a support engineer’s laptop" is very vague, they could have:
1. some kind of remote access to the support engineer's session on that laptop
2. physical access, no login
3. physical access as a different user
4. physical access, logged in as the support engineer
If I have access to your laptop, logged in as you, and you have Gmail open in a browser, then your Gmail account should be considered compromised. (e.g. I could set up a forwarding address in your Gmail settings, set up a POP/IMAP password, steal your session/remember me cookies, install some dodgy software which makes sure I have remote access to your laptop in the future, etc..).
- nopcode 5y agoAccess to the laptop could also be completely unrelated. The threat actor used a breached Thin client to access Okta...