If you compromise a computer, you can compromise web sessions. There is no mitigation for this. Shame on the author for attempting to create panic when far more productive security can be achieved elsewhere.
If you compromise a computer, you can compromise web sessions. There is no mitigation for this. Shame on the author for attempting to create panic when far more productive security can be achieved elsewhere.
AND filesystem access IS a concern, and that is not just if someone has physical access. E.g. You do not know for sure that the code running on your own system was designed with your interests in mind.
Intentionally or by mistake, a password database file could be leaked and broken into if uploaded to a server on the internet outside of your control, and if they also upload your encryption key along with it, goodbye passwords. It could be as simple as a piece of software uploading "telemetry" data, and "accidentally" including the password database from a browser along with the encryption key.
I don't think that's a valid approach anymore. FWIW I have coded these restrictions into auth tokens before (i.e. reject the auth token if it's from a new IP), but had to get rid of it because too many ISPs frequently change a user's IP address, especially mobile clients.
If the user's passwords to the rest of the corporate systems are sitting unprotected in a browser password store, it is a gold mine.
Yes, they should have 2fa and single sign on and so on, but many places don't. The article isn't terrible, it's just pointing out something in browsers that works ok for home users but puts businesses at some risk.
/me not a security expert. But isn't this the mistake I used to make for years: to believe that the hacker is a human, responding to his environment and making decisions? It took me a long time to acknowledge that nearly all network attacks are automated, and unless it's a highly targeted attack, the attack script won't care whether you're a corporation or a couch-potato in a basement.
But the sinister targeted ones where you only find out because someone is selling terabytes of confidential data, those are usually highly targeted and manual. It's very hard to automate and stay under the radar.
You need protection against both.
It doesn't surprise me that "sinister targeted" attacks are also "usually highly targeted".
People still have this idea of the lone hooded hacker doing everything from their bedroom.
In reality, people specialise in different aspects of cracking security and sell what they have to someone else. So someone is in the market for a zero day, or a compromised system in the government or a company, and they can just buy that.
For home users, the payoff isn't big enough to be worth more than automated type attacks. So you escape the human in the loop mostly.
If you work on highly sensitive systems then you should expect a human in the loop at some point.
I don't; I'm retired. I have only my home network to fret about. I don't have data to lose, but I don't want some rotter using my network to attack other networks. That rotter isn't going to set up automation to grab my family photos; but he'll use automation to attack other networks.
I've never worked with "highly sensitive systems", as far as I'm aware. I've only ever worked with systems that had the potential to wreck the company. I don't know if that counts, in your book.
My own home security is merely adequate. I turn off things like upnp on the router. Disks and backups are encrypted. I don't worry overly much about it. If someone actually targets me it's probably game over, but it's ok against random script kiddies or someone stealing my computers.
So you think this isn't the case with home users? Maybe I still misunderstand the point that is being made here, but from my perspective it's only a matter of time until my encrypted password store gets exposed to the local attacker (as soon as I unlock it).
So that default browser behaviour creates a risk that a business should acknowledge and assess.
A home user can of course also decide it's too risky, or that password managers are too risky and only a yubikey will do.
If your point is that password managers aren't a total solution to the issue, I'd agree.
- Sessions can be linked to a user's location and/or browser finger print
- Sessions are short(er) lived
- Sessions can easily get invalidated (e.g. device wide logout)
- Almost all critical actions are behind additional security (e.g. can't change password without 2FA or change billing information without confirming password and/or 2FA in order to apply changes, etc.)
- Sessions are not shared across properties, whereas many users share their password across multiple internet sites/properties
Does this still really happen??
I've given up that malpractice years ago.
Unfortunately it's very hard to gauge this in our company but I would hope users take their security training to heart.