3 ms·
Impressive investigation and mitigation! My lingering question however is still how come the phishers knew so much about cloudflare, yet missed the critical ke
by gingerlime 4y ago
Impressive investigation and mitigation!
My lingering question however is still how come the phishers knew so much about cloudflare, yet missed the critical key (no pun intended): they had 76 phone numbers of CF employees and a plausible call-to-action, plus knowledge about okta usage, but missed the crucial fact that CF uses hardware tokens??
- mike_d 4y agoThe attackers hit over 300 organizations in less than 48 hours. Cloudflare just happened to be slightly different enough that it broke their automation. You can see some of the other victims in public CT logs: https://search.censys.io/certificates?q=%28%28Okta.com%29+AND+tags.raw%3A+%22ct%22%29+AND+parsed.issuer.organization.raw%3A+%22Let%27s+Encrypt%22& https://search.censys.io/certificates?q=%28%28Okta.com%29+AN...
- tialaramex 4y ago> Cloudflare just happened to be slightly different enough that it broke their automation. This type of attack just can't work on targets which are properly secured with FIDO authenticators. So it's not really "slightly different". The minimum adjustment the attackers can make is probably something like "Hire motorcycle couriers, add a step where the user is told their token needs replacing, a courier comes out and takes it, we get the token". Which is a very different ball game from "Make some web sites and install this off-the-shelf phishing toolkit".
- mike_d 4y agoFine. But by Cloudflare's own statement it didn't fail because they used webauthn, it failed because they didn't use TOTP. Think of it like a bank robber showing up to a job to crack a safe with an autodialer. He will have no problems on 9/10 banks that use dial safes, but this one has an electronic keypad. The electronic keypad being better or worse is irrelevant, it protected the bank because the robber brought the wrong tool.
- jgrahamc 4y agoNot really. Because the hard keys are bound to the origin website it wouldn’t matter if the attacker had been aware. It still wouldn’t have worked.
- mike_d 4y agoThey also didn't try to steal eastdakota's laptop, yet you give no credit to the (I assume) perfectly good locks on his home.
- _8j50 4y agoIt was mos likely not targeted. The fact that theh forked up the cash for yubikeys is the only thing impressive everything else is standard incident response. This seems to me like a credential harvesting campaign. Most likeli there is a trojan app that was used which used a list of contacts to spread. It noted that the employee's families were also contacted, this tells me CF does BYOD for mobile phones. I make a point out of not using my personal phone for anything work related because of this and many other reasons. Not only should companies pay for and manage employee's work phones, using a personal phone for work reasoms should be disallowed. Work phones can be restricted to not have unapproved apps. While yubikeys are phish proof, the attackers could habe instead asked users to download an authentication app which would steal cookies to bypass yubikeys by letting them login to the right CF portal but in a trojanized in-app browser.