1 day ago · Tech · hide · 0 comments

"For safety, don't click suspicious links" Meanwhile, most organization's login flow redirects through: # This is a real example, but I've changed the names to avoid pointing fingers https://www.[name of company].com/squawk/ https://login.[name of company].com/ https://login.smallcrow.com/324aa78a-03a6-66fc-23e1-4124fdsa213 https://experience.crow-cloud.com/[name of company]/auth https://flock.auth.bird-security.com/authorization https://api-deadbeef.bird-security.com/oauth/v1/authorize?token=DeAdBeEf https://api2.bird-security.com/2fa https://www.[name of company].com/cool/bird/ https://experience.crow-cloud.com/[name of company]/ https://www.[name of company].com/squawk/ Neither the username, password nor 2FA code prompts are hosted on the company's own domain. Combine that with constant login expiration triggering random authetication pop-ups, and it's nearly impossible not to be phished ... because the real thing looks indistinguishable from a scam: All an attacker needs to do is…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.