Hacker News new | past | comments | ask | show | jobs | submit login

> If your user env is compromised its too late

How to recover from a "my env was compromised" situation? Do you recommend just say good bye to this world and commit suicide?

If not, this change makes the recovery easier: I just need to (worst case) destroy the compromised device and I can be confident that nobody is hoarding a valid credential to my online banking account which they may choose to empty (again) years later.




> How to recover from a "my env was compromised" situation

depends on the scope of the compromise, its an open ended question with lots of rabbit holes dependent on backups and other stuff.

but as others mentioned: logging out of all sessions is a good start from the <bank, ect> side... people should be logging out of sessions anyways when not logged on a particular sites webui.

we are at a fun time when browsers have too much access (and javascript <reminds me of Flash>) to the host system that they are themselves are the OS (its been this way for many years)... the bigger issue are the websites that dont auto logoff, that have really poor password compliance, and even worse encryption of their own systems. a compromised system also means your password vault is compromised too given that it is in the same env. a more complex solution would be to have your keepassdx on an internet-less system and your browser on another system where a user logs off explicitly, if not automatically). then syncing bookmarks and play-time and sites-ive-visited can be less of a 'my whole account session' got compromised


Log into the bank and click the "log out of all sessions" to invalidate all cookies. Or if an attacker changed your credentials walk into the back and have a banker do it and then have the show/reverse all changes and transactions the attacker made. If the option does not exist, demand they add it or you and your money will go to another bank. Not all websites have this option but they would if enough customers demanded it.


Not all applications provide users with the option to log out of all sessions.

Web Applications today, could do several things without the help of Google to make cookies more difficult to be stolen but they don't.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: