View Single Post
Old 3 Oct 2019, 07:49 AM   #1
gardenweed
Cornerstone of the Community
 
Join Date: Jun 2008
Location: Perth
Posts: 664
General Security & ANU Hacking

The article in this link describes email hacking that happened to Australian National University (ANU).

It says that:
Quote:
The cyber attack was so sophisticated it didn’t even need the person to click on a link or open a document to compromise decades worth of private information.
and
Quote:
A person working closely with that staff member previewed the email before deleting it — but it was too late. Merely previewing the email was enough for hackers to steal a username and password that opened the first door into the ANU network.
Although this is general discussion about email security, I am raising here in the context of Fastmail usage and what FM offers for protection.

I'm curious as to how "previewing" an email could result in login details being stolen.

I use the FM web interface 95% of the time, however every now and then I have a reason to use my FM account with MS Outlook or Thunderbird. Obviously they have the required App passwords.
Also, for web login, I have 2-factor set with hardware key.

I'm wondering what the circumstances would have been to allow so called previewing of an email (what does this even mean) to allow stealing of login credentials and whether my usage of FM could place me in the same vulnerable position.

Welcome discussion on this....
gardenweed is offline   Reply With Quote