5 ms·
This is quite interesting. A couple of weeks ago, I received an extortion phishing email, but it was directed to a secondary email address that hasn’t been prev
by ern 4y ago
This is quite interesting. A couple of weeks ago, I received an extortion phishing email, but it was directed to a secondary email address that hasn’t been previously compromised. It made it past Gmail’s spam and phishing filters into my inbox.
Maybe a coincidence, but I guess every weird thing that happens is going to raise alarm bells.
I was suspicious of the LastPass concept (storing passwords in a cloud app) when a former employer introduced it some years ago, but they had a strong IT and security culture so I trusted them to make the right choices and adopted it for my personal use.
A few months ago I hsd an issue with my LastPass 2FA device and a policy set by my former employer blocked me from resetting it for my personal account. It was resolved by LastPass, but that was the first strike, and I had spent most of the night extracting my personal account passwords manually from the mobile app, which remained logged in. That was strike 1. This is strike 2.
- bigiain 4y agoI’d love to hear the story about bypassing/resetting that 2FA setting? Sounds suspiciously like something that could be social engineered around by a sufficiently skilled attacker? I am very much of the opinion that if I fuck up my side of 2FA protection, the resources/accounts they’re protecting should be lost forever. (Or at the very least, a co-account holder might be able to reset some things, like my AWS IAM creds or GSuite admin account). If I can ring up and whine at enough support people to get them to hand over my account, so can a sufficiently persistent skilled social engineer…
- ern 4y agoFair enough. It was a support request, and IIRC they disabled it remotely.
- bombcar 4y agoAny two factor that doesn’t require your firstborn or travelling in person to some frightening building to remove is basically a form of security theater. Most can be removed by support pretty easily just by asking.
- michaelmrose 4y agoWhy would support be in the business of removing it just because someone asks? If I needed it removed I could take a call at my official phone number and photograph my actual ID. My cell provider requires a photo ID in person or a long pin not stored in the same place as other passwords in order to assign my number to a new phone and 2FA to access account. This raises the bar from knowing my password to knowing my password, knowing my ID, producing a fake facsimile of my ID, stealing my pin from its encrypted container on my desktop, taking over my phone number, then taking over my account. I don't have a pile of crypto to steal ergo this would be a LOT of work to send spam as me until my email gets flagged. It would be like a heist movie only with the target being the $40 in my wallet. mission impossible themesong begins playing Basically support just needs to exercise reasonable caution when removing or changing it.
- mbar84 4y agoOn a balance of risks, your your former employer may have made the right call. The issue is, do you use something that isn't perfect but everybody can use, or do have a substantial portion of tech illiterate people not use anything, which would be an even greater risk.
- ern 4y agoI think the policy is fine, but since I left my former employer more than a year ago, the policy should have been lifted on my personal account automatically (assuming that my former employer deactivated the work account, which I expect that they did).
- beardedwizard 4y agoI had exactly the same experience, and I even filed a bug in the bounty program about it 4 years ago. In my case I was off boarded by an employer, but retained access to it on my mobile device and could read all passwords. Their initial response was that it was by design, then later tried to pay a bounty I never accepted.
- dylan604 4y agoStrike 2? This is strike 3 of the final out of the 9th inning. AKA game over.
- isthisthingon99 4y agoSame thing for me with sudden spam emails. But the receive address did not have the customization for me to track it, instead my first name. Not sure if lastpass related but maybe. BTW one client of mine runs a heavy security operation and they use KeePass.