6 ms·
I think if I were concerned, I'd try creating a honeypot account on some service that notifies me when someone new logs in (like google). Then I'd log into that
by QuantumYeti 3y ago
I think if I were concerned, I'd try creating a honeypot account on some service that notifies me when someone new logs in (like google). Then I'd log into that account sometimes while playing the game and monitor it for any new logins. It still could have a keylogger even after all that, though.
- Woeps 3y agowait, I'm lost. So lets say we have a software, and your account can tell you when somebody else sees your info in this piece of software? How would this work? And what does this have to do with keylogging? Genuinely asking as I'm just trying to understand what link I'm missing
- QuantumYeti 3y agoSorry, the assumption I left out is that whoever is running the keylogger would see you logging into a "valuable" account during their logging and then try to access it. Since it'd be a new account with nothing on it, there's nothing for the attacker to really compromise, but you could get a notification letting you know someone new logged in, which would let you know that someone successfully captured you logging in.
- luismedel 3y agoThis is the most direct way to know if you're being spied. This, and having a honeypot URL that warns you each time it's visited. Any other way can be easily circumvented. In theory, any smart enough malware could hide itself in presence of any kind of analysis tools.
- reallynotsure 3y agoThat's upsetting! I got 3 alerts so far within the last 5 months about suspicious logins (from Twitter, Facebook & Google). I was dismissing it telling myself I am being paranoid. Now I think my employer itself is spying on me? The first alert was from Twitter. I am an H1B from India employed by a WITCH type Indian company working for an US client (probably top 3 in the world in what they do). One day, I saw some Twitter posts about how greencards for Indians would take decades or even 100 years. I was talking about this to a colleague on client's Microsoft Teams. Just as I mentioned this, teams got disconnected. Later that day, was talking to another colleague through same teams about same topic, again got disconnected. I thought it was odd, but dismissed. Then around 9 pm same day, I get an alert from Twitter that they prevented a suspicious login from an IP address in US. 4 weeks ago, I was talking about how my WITCH company manager is not letting anyone take vacation (from Sep-Dec, they are not letting any one take vacation unless absolutely necessary) to another colleague, through client's teams. 3 days later, I get an alert from Facebook that someone accessed by account, this time from Turkey. Then 1 week later, got an email from Google with a security code that someone had requested for accessing the same Google account. Don't know if I should just pack up and leave US at this point, lol!
- K0balt 3y agoI would enable cryptographic 2FA on all of my accounts where it is possible and run the 2FA on a discrete device (token dongle or an old phone with wifi and Bluetooth off, no sim)
- QuantumYeti 3y agoI made a FB account to change a client's Page settings, and now I pretty regularly get emails from FB along the lines of "Having trouble signing into your account?" because there's been tons of failed repeated logins. I think it might just be a normal part of having a FB account? Can't speak for the other services.
- 0xDEAFBEAD 3y agoThat doesn't sound normal to me. You should tell your client that someone might be trying to hack them.
- evilduck 3y agoFirst, why are you accessing personal accounts on a company computer? That's reckless all by itself. Your personal information is up for discovery if the company gets into any legal problems. Keep your professional and personal computer uses separate. There's absolutely zero reason you need to be logged in to your personal Facebook and Twitter accounts at work. Second, Twitter, Facebook and Google all provide enhanced account security options like Passkeys and MFA and it's clear you're not using them. Turn them on (and using your personal devices, not your work provided items) and your employer or any other random hacker is going to have a substantially harder time accessing your accounts.
- 0xDEAFBEAD 3y agoAre you sure they're accessing personal accounts on a company computer?
- evilduck 3y ago