4 ms·
As purely an outsider and not OP: it seems their contractors and support people have direct access to critical customer data simply by typing password and/or to
by dividuum 4y ago
As purely an outsider and not OP: it seems their contractors and support people have direct access to critical customer data simply by typing password and/or totp into a form. Seems it’s not always the correct one.
* Limiting access (maybe to email subject instead of all content?) might prevent some fallout as it might be more difficult to extract password reset emails sent by customers.
* Limiting access from certain IP sources might make it more difficult to use captured login credentials.
* Hardware key based authentication might prevent the type of phishing that seems to have happened here.
- iamacyborg 4y ago* Allowing customer to only allow MC staff access for fixed intervals when support tickets are raised.