←back to thread

1369 points universesquid | 5 comments | | HN request time: 0.001s | source
Show context
paxys ◴[] No.45174186[source]
Yeah I know "everyone can be pwned" etc. but at this point if you are not using a password manager and still entering passwords on random websites whose domains don't match the official one then you have no business doing anything of value on the internet.
replies(6): >>45174727 #>>45175611 #>>45176385 #>>45177993 #>>45179019 #>>45179128 #
1. Drblessing ◴[] No.45176385[source]
How does someone intelligent with 2FA get pwned? Serious question.
replies(2): >>45176768 #>>45178922 #
2. odie5533 ◴[] No.45176768[source]
Numbers game. Plenty of people got the email and deleted it. Only takes one person distracted and thinking "oh yeah my 2FA is pretty old" for them to get pwned.
replies(2): >>45177288 #>>45177293 #
3. pier25 ◴[] No.45177288[source]
It's more than that. You need to log in, manually, into a new domain you've never used your password before.
4. CGamesPlay ◴[] No.45177293[source]
(I think everyone in this comment chain already knows this, but) PSA: your 2FA does not "get old" and does not need to be rotated (unless the device YOU stored it on was compromised). "Rotate your 2FA periodically" is NOT recommended security advice.
5. Mawr ◴[] No.45178922[source]
Thinking you're above getting pwned is often step one :)

It's not easy to be 100% vigilant 100% of the time against attacks deliberatly crafted to fall for them. All it takes is a single well crafted attack that strikes when you're tired and you're done.