6 ms·
Being reminded of this anecdote from NYMag's recent cover story (which had previously been reported in a WSJ story[0]) about a Disney engineer who downloaded an
by danso 4mo ago
Being reminded of this anecdote from NYMag's recent cover story (which had previously been reported in a WSJ story[0]) about a Disney engineer who downloaded an AI-gen tool from Github and "checked the code himself, it had looked legitimate":
https://archive.is/yAUNy https://archive.is/yAUNy
> He had no idea why the hackers had targeted him or what their plan was, whether they would drain his family’s finances or stalk his home. Eventually, after running another anti-virus program, he found a piece of malware hidden in a plug-in he had downloaded from GitHub, the open-source coding site, one day in February when he was messing around with an AI image generator. He had checked the code himself, it had looked legitimate, and others had reviewed it positively. But it seems it contained a Trojan-horse virus that gave the hackers free rein of his PC. Once inside, they just had to wait for Van Andel to log in to 1Password. From there, they were able to steal all his credentials, plus many of his multifactor-authentication codes, so every time Van Andel logged in to an app, a website, or an account, they could follow behind him. They’d had access for months.
[0] https://www.wsj.com/tech/cybersecurity/disney-employee-ai-tool-hacker-cyberattack-3700c931 https://www.wsj.com/tech/cybersecurity/disney-employee-ai-to...
- tedd4u 4mo agoStrong support for the strategy of not putting your TOTP/MFA in your password manager, which has been argued on HN in the past.
- Terr_ 4mo ago> putting your TOTP/MFA in your password manager I suppose the inverse would be starting with a device that offers TOTP/MFA, and then making your password-manager/vault somehow available on that same device. In either case, bringing them together makes it easier for an attacker to compromise both at the same time. On reflection, I've never actually put my (personal) password vault on my phone, but that may be less of a conscious security stance than fulfilling a millennial stereotype, where certain tasks (like big purchases) are reserved for "a real computer." Closest I've gotten is having my USB backup keychain in the same pocket, so I could get to it in an emergency, but it's inconveniently air-gapped.
- rectang 4mo agoAs much as I like the Apple Passwords app, one of its downsides is that if I have my TOTP app on my iPhone, both passwords and TOTP live on the same device. So for many services I use Bitwarden for passwords.
- mcfly_c-137 4mo agoFor TOTP i use ente auth[0], which i can higly recommend. i also force most apps on iOS to ask for face id (long press on app icon to set this). [0] https://ente.com/auth/ https://ente.com/auth/
- toomuchtodo 4mo agoOr using a hardware authenticator.
- rolph 4mo agoi would also offer, do not use the same device for everything, make sure any local connectivity has firewalled [dot]finances, and [dot]tech lab from each other and else. you should probably split your network to further isolate. use intentional spelling mistakes in your password vault, edit the password by hand. you also need to have some way of authenticating login components to be sure your running your version of login, and not a trojan login.
- 8cvor6j844qw_d6 4mo ago> Strong support for the strategy of not putting your TOTP/MFA in your password manager Agreed, but I think using the same device to access your password manager and for dev is asking for trouble in the first place. Password managers assumes a non-compromised device. I don't think there exist a password manager that is explicitly designed for a compromised/hostile device. A password manager + built-in TOTP on a dedicated device is fine for most general usage. Important TOTPs can go to Yubikeys.
- deepsun 4mo agoBut it's a hassle to have at least 2 yubikeys in case you lose one. And since you regularly sign up for new websites with OTPs, gotta keep them in sync. So always carry both with you. And if you carry both, then it's easy to lose both at the same time. UPDATE: also gotta keep track separatelt of non-resident passkeys tied to Yubikey, because Yubikey doesn't know where it was used for non-resident. If you lose one yubikey, need to sync all passkeys to a new replacement one.
- zygentoma 4mo agoWould be nice if you could get an exact clone of a yubikey, so you always have a spare in case you lose one. Though I think there is also the option that sites can store some sort of identifier on the key, then this would not work:/
- cuu508 4mo agoI add a note in the password manager's notes field for sites where I've added Yubikeys as the second factor. I can get the list of the sites using search, and from time to time I go through them to check if a backup key needs to be registered. I create new accounts infrequently.
- 14u2c 4mo ago>Agreed, but I think using the same device to access your password manager and for dev is asking for trouble in the first place. That seems somewhat unrealistic? There are many passwords you need to use as part of dev work.
- uncivilized 4mo agoStory states he wasn't using 2FA for his 1password account at all.
- mixdup 4mo agowhy was he even bothering then
- cdmckay 4mo agoYou can make it so you need a YubiKey to login to 1Password the first time on a new device So just waiting for the password won’t be enough
- auxinl 4mo agoThe hackers will literally have access to _your_ device though. If your device is already trusted, I doubt that setting will do you any good.
- criddell 4mo agoOn Linux, would something like Snap or Flatpak have protected them? It seems nuts that a random executable should have access to the password service.
- embedding-shape 4mo agoUltimately it depends on the exact mechanism here, maybe the tool/README said "Run sudo ./setup-deps" and they followed it, or something similar, not sure any sort of software isolation would have helped at that point.
- Gigachad 4mo agoYes if the flatpak sandboxing is enabled. A flatpak can just request access to anything, the software store thing shows a bunch of scary warnings when they do this but many users probably ignore them.
- frereubu 4mo agoI think this is true in technical terms, but I have not seen a compelling description of what that looks like without it sounding like a real pain to manage. Does anyone have a description of something manageable?
- schrodinger 4mo agoWonder if you could run your password manager in an isolated sandbox that couldn’t provide the secret behind the TOTP, only the current value.
- GoodPepper50 4mo agoSeparate and additional auth service based on physical ownership is always nice!
- hibikir 4mo agoAt the very least, a different account for your password manager at work, hopefully paid by the company, which you don't install outside of company-controlled devices.
- giancarlostoro 4mo agoIf I go through the effort to view the code for something, I then compile it myself.
- hnlmorg 4mo agoWhat makes you think he downloaded a pre-compiled binary? The link article doesn’t explicitly say that’s what happened. It just says he downloaded software from GitHub. Which might well have been the source code that he then compiled.
- giancarlostoro 4mo agoLooks like it was some comfyui plugin, so probably didn't even need to be compiled.
- WalterBright 4mo agoA password manager is a single point of failure and should be avoided. I've heard other sad stories about someone who's pw manager was compromised and they lost everything.
- pksebben 4mo agoout of curiosity - what scheme do you suggest? I've always been of the mind that 'one thing to remember and secure, but secure it well' was the best option - 2factor and a 15+character passphrase meaning that nearly everything else gets it's own discretized blast radius. Always open to better security, though.
- WalterBright 4mo agoHave a different password for every account, and don't store them on your computer.
- rurban 4mo agoTrue for KeyPass or 1Password, but not for GNU pass.
- hnlmorg 4mo agoWhile you’re not wrong in principle. It’s still the least worst in the vast majority of cases. I think the bigger problem is using your pw manager for 2FA too.
- lachlanj 4mo agoWhat do you suggest as an alternative?