TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How Reuters got compromised by the Syrian Electronic Army

5 点作者 Hoff将近 11 年前

2 条评论

apaprocki将近 11 年前
What's more plausible -- Google 2-factor was disabled, or a user re-used the same login/password on a site without 2-factor? Passwords will be with us for a long time to come. Employers should buy employees 1Password or equivalent for their own safety and require long unique random strings for every 3rd party account. Employers can control that somewhat but can't force vendors to implement 2-factor.
matheusbn将近 11 年前
[TD;DR]<p>It wasn&#x27;t a problem inside reuters, but their 3rd party provider called (Taboola), which injects ads on reuters. So once Taboola hacked, the ads system started injecting a script to redirect that page to another one.<p>Finally: Be careful with those 3rd parties ads tools etc.