GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 03-Apr-2025 02:21:39 JSTKevin BeaumontKevin Beaumont
    in reply to

    100% on this one, seen all the time on real world incidents.

    Problem: somebody got a password for an account and nobody knows how.

    How: the business user signed into their personal Google account in Chrome at work, which synced all their bookmarks and saved passwords to Google. Then they switched on their home PC, Chrime synced, and infostealer took all the details

    Solution: Google Chrome ADMX, and set Group Policy to turn off personal account sign in with Chrome.

    https://infosec.exchange/@Walker/114268652560517693

    In conversationabout a month ago from cyberplace.socialpermalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Walker (@Walker@infosec.exchange)
      from Walker
      @GossiTheDog@cyberplace.social The larger problem for corporations is browser sync for passwords, login cookies and tokens, and other sensitive data. Home PCs do not have advanced EDR and if it gets compromised that could expose corporate resources.
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.