Skip to content
Discussion options

You must be logged in to vote

Hey, thanks a lot for the detailed reply.

As a quick measure, change passphrases everywhere (including ssh and borg key, but also e.g. for your e-mail accounts).

I have done that. All critical ones (email host, domain registrar, finance, storage etc) were changed within minutes and some more later and since then I have been on the rest of those.

About

how probable it is that attacker has stolen passphrase AND borg repokey

My layperson's analysis indicates the attack failed because I didn't provide my Mac password and disconnected the Internet within seconds of first password popup which literally was at the script start.

The attack was pretty much this. I copied the script from the ru…

Replies: 3 comments 3 replies

Comment options

You must be logged in to vote
1 reply
@RonnyPfannschmidt
Comment options

Comment options

You must be logged in to vote
2 replies
@justauserid
Comment options

Answer selected by justauserid
@ThomasWaldmann
Comment options

Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants