A very exploitable bug that is designed that way?

800 Views | 2 Replies | Last: 15 days ago by tomtomdrumdrum
eric76
How long do you want to ignore this user?
AG
From https://cybersecuritynews.com/vaultjacking-attack-steals-entire-google-password-manager/

Quote:

A new phishing technique called VaultJacking has emerged, and it is raising serious alarms across the cybersecurity community. With just a single captured 6-digit PIN, an attacker can walk away with an entire Google Password Manager vault, including every saved password and passkey stored inside.

...

Every third-party login, every stored passkey, and every saved credential instantly becomes accessible to the attacker operating from behind the scenes.

...

Security professionals should treat this as an accepted-design trade-off rather than an unpatched bug awaiting a vendor fix.


So if you use Google Password Manager, you need to be very wary of any e-mail wanting you to enter your pin. Google doesn't seem interested in doing anything about this.
Nealthedestroyer
How long do you want to ignore this user?
AG
Can't get my pin if even I don't know it…
Vae Victis
tomtomdrumdrum
How long do you want to ignore this user?
AG
"a single captured 6-digit PIN" and access to your google account. If your google account is compromised, you're in trouble anyway - just don't get phished.
Refresh
Page 1 of 1
 
×
subscribe Verify your student status
See Subscription Benefits
Trial only available to users who have never subscribed or participated in a previous trial.