A Hidden Cost of Ransomware: Wholesale Password Theft
krebsonsecurity.com
krebsonsecurity.com
“In mid-November 2019, Wisconsin-based Virtual Care Provider Inc. (VCPI) was hit by the Ryuk ransomware strain.”
In 2020, this is not acceptable in terms of “computer” security, where opening an email attachment or clicking on a malicous link can totally compromise your business. The planets chief software architect has a lot to answer for.
Something you have + something you know are multiple factors.
There should still be a password. If there isn't, then it's single factor auth.
Also, SAASPASS looks really interesting. Thanks for sharing. Going to take a much deeper look into this now.
EDIT: Nope, change of plans. The account recovery flow depends on SMS, which isn't safe given how easy SIM-jacking is: https://saaspass.com/how-to-recover-saaspass-id-account/
So now the password isn't in the computer at all and can't be stolen from it.
For example to sign into the web site for my bank account I need to enter a PIN into a chiclet keypad device they gave me, it spits out a one-time code and I type that into the web site. You can't steal the PIN from my PC, even if you have some kind of super zero day exploit and co-operation from the OS vendor, because the PIN gets typed into a separate device that doesn't even have a USB connector. You might as well try to use the PC to steal cash out of my wallet.
The parent's whole point was that this service doesn't have a master password. Nope, instead it has a 4 digit PIN and SMS as it's base flow, with security as an optional extra.
A password manager shouldn't need to be caveated to be recommended. It's too important for that.
only if enabled. Just like any password manager out there.
It is hard to defend against, unless you want a system that constantly prompts you for your password everytime you want to do something. Frequent password prompts is not really good for security either. Current mitigations really just slow down the attacks and gives you time to respond. If they are left alone they will manage to gather credentials over time.
https://github.com/gentilkiwi/mimikatz https://www.sans.org/reading-room/whitepapers/detection/mimi...
It's pretty complicated and requires server 2016 or windows 10. More info here - https://docs.microsoft.com/en-us/windows/security/identity-p...
How about running the OS in a Virtual Machine, that evaporates on exit and you get a new clean image on each invocation.
“All the King's horses and all the King's men couldn't put Humpty together again”
https://www.youtube.com/watch?v=tTl5Rl8cKy8
"Gig05 Pen Test War Stories Why my job is so easy and how you can make it harder Aaron Herndon"
It sounds like this attack was by a more sophisticated group that compromised some initial system in that way, and then somebody actually went in to explore and determine how to spread the compromise around further. It seems to be difficult indeed even for large and sophisticated companies to defend against these types of attacks. Since somebody, or a team of people, has to do most of the compromising manually, they naturally demand higher ransoms.
There are a lot of networks out there with fileshares configured far more permissively than they should be. Additionally, if the malware infects a machine that has cached domain admin credentials stored on it, it can use those to authenticate to the rest of the network and own the entire domain.
Yes, if best practice is followed, these tactics wouldn't work. Best practice is not always followed.
Privilege escalation: https://www.fuzzysecurity.com/tutorials/16.html
And if the company has everyone save their work on a shared network drive that lots of users have write access to, you don't even need to spread to other computers.
Plus of course, there are the classic means of spreading within a network - scan machines on the network for vulnerabilities, infect anything executable on shared drives, phishing e-mails that genuinely come from another employee's computer, keylog or brute force an admin password....
Seems related to something called "Hello"? Either way, I haven't found a way to disable it. Caveat emptor.
1. Let the Hello stuff happen, GitHub will propose that you name it, why not "Hello".
2. Tell GitHub you want to enroll another token. The system will automatically disregard "Hello" because that was already enrolled, so this time it will enroll your Yubikey or whatever other tokens.
3. (Optionally, if you don't want "Hello" e.g. because it isn't your Windows PC you just borrowed it) Tell GitHub you want to remove "Hello".
Also I am a bit of a scatterbrains so prone to losing things. What do I do if I lose my YubiKey, are there recovery options?
Do you use it in addition to an authenticator app or instead of? I am really confused as to the advantages it gives.
The web site will need to support FIDO U2F, yes.
> Can I just use it for 1Password?
I've not used 1Password, so I don't know. The Yubico site should be able to tell you if a given thing is compatible.
> What do I do if I lose my YubiKey, are there recovery options?
Nope. Get two of them.
> Do you use it in addition to an authenticator app or instead of?
Sort of both. So if a site supports the use of an authenticator app but not FIDO U2F, I use the Yubico authenticator app. When opened, it stays locked until my Yubikey is tapped against my phone.