Hi everyone,

I’ve implemented strong security measures like 2FA, password managers, and even security keys to protect my accounts. Despite all this, I’ve still experienced hacking incidents that don’t seem to fit common explanations like session hijacking or phishing.

I’m trying to understand what advanced attack vectors or vulnerabilities might be at play here, and what steps I can take beyond the usual advice to secure myself better.

Has anyone faced similar issues or can share insights on deeper cybersecurity operations, attack methods, or advanced defenses? What should be the next steps when standard protections fail?

Thanks in advance for your expertise!

  • red_teamer@infosec.pubOP
    link
    fedilink
    arrow-up
    1
    ·
    10 天前

    Your assumption is partly correct regarding storing passwords and passkeys in Bitwarden. However, my MFA is managed separately through Google Authenticator, and the recovery codes are stored in a separate account that itself is protected by multifactor authentication, including access only via a hardware security key.

    Additionally, my Bitwarden account is secured with a 32-digit random master password, multi-factor authentication, and a security key.

    So while I understand the potential attack vectors you mentioned, I’ve taken steps to keep these components isolated and strongly protected.