Anyone know the details of how this actually works? Does it mean browser cookies? How do cookies end up being sold in this way?
Anyone know the details of how this actually works? Does it mean browser cookies? How do cookies end up being sold in this way?
If someone managed to get some malware running on a machine where you have logged into slack it's fairly trivial for someone to get your cookie. Something like https://github.com/djhohnstein/SharpChromium is an example of a tool used to pull browser cookies off a compromised host.
I don't know the explicit details of this particular instance, but I imagine the user in question had some kind of malware installed on their phone or computer. ( I keep seeing mention of a browser extension in the comments, and I have seen some working examples of malicious chrome extensions recently that would let you steal cookies once installed.)
A corporate MITM proxy does has it own certificate authority, or else it wouldn't be able to monitor its traffic like it's expected to do.
But no, it sounds like Slack doesn't do that, which is a problem.
Also include a timestamp to force re-authentication at some point.
This isn't rocket science.
A private key shouldn't be device dependent. 2FA was the solution here, but was not enforced properly. They were able to social engineer IT into resetting their 2FA token without any proof they were who they said.
Sure it's not perfect in a world where IP are not necessarily static (and a VPN may change it), but having to login again is not that bad, even more so if you are using SSO.
No good. Slack's biggest userbase is corporate, behind corporate VPNs. Many users have the same IP.
(Especially if it's a user who isn't in a corporate environment, where your public IP will probably differ when you connect to different wireless networks. On a corporate network you're more likely to retain the same public IP no matter which room or building you're in.)
If they don't, they should provide an option for corporate administrators to enable IP locking for session cookies.
Logging people out also isn't a minor inconvenience, especially for users who haven't figured out password managers yet.
I know this isn’t actually a major thing. It’s a 20 second process. Still a couple times a day is a couple times a day.