2 ms·
Andrew Miklas wrote in a comment: The attacker gained unauthorized access to an administrative panel provided by one of our hosting providers. There have been
by andreasley 11y ago
Andrew Miklas wrote in a comment:
The attacker gained unauthorized access to an administrative panel provided by one of our hosting providers.
There have been several breaches in the last months where this was the main cause and it's something almost impossible to defend against – unless you're running your own datacenter hardware, which is very hard to get right.
Few providers properly secure their control panels with 2FA, even though these admin panels are an attractive target and almost always provide full access to the system.
- rdl 11y agoEven 2FA as commonly implemented is kind of a bullshit solution (it's once per 30 days, it's not on every transaction, it's not specific to the transaction, there's no enduring log, no concept of segregating various types of action, no concept of callback auth/validation, often not multiuser/shared credentials, etc.) Consumer-style 2FA protects somewhat against brute force, against password reuse by users who just don't care, and against theft of a whole password list. It doesn't actually protect the protected resource very much.