메뉴
BL
Ars Technica 55일 전

대시레인, 20개 암호화 금고 탈취 경고

IMP
7/10
핵심 요약

비밀번호 관리자 대시레인(Dashlane)이 외부 공격자의 무차별 대입 공격으로 인해 20개의 사용자 암호화 금고가 탈취되었다는 보안 권고문을 발표했습니다. 하지만 공격에 사용된 2차 인증(2FA) 우회 방식이나 기존 비밀번호 유출 여부 등 핵심 설명이 부족하여 사용자들의 혼란과 우려가 커지고 있습니다. 이 사건은 2차 인증 체계의 취약점 가능성과 보안사고 발생 시 기업의 투명한 소통이 얼마나 중요한지를 보여줍니다.

번역된 본문

비밀번호 관리자 대시레인(Dashlane)이 월요일에 게시한 보안 권고문에는 공격자가 20개의 암호화된 사용자 금고를 확보하는 데 성공했다고 경고하고 있지만, 이 사건에 대해서는 전혀 맞지 않는 점이 많습니다.

회사 측은 "2026년 5월 31일 일요일부터 외부인이 특정 대시레인 사용자 계정에 대해 무차별 대입 공격(brute force attack)을 시작했다"며 "이 공격의 목적은 2단계 인증(2FA) 보호 기능을 무차별 대입으로 공격하여 공격자가 기존 사용자 계정에 새로운 기기를 등록할 수 있도록 하는 것이었다"고 밝혔습니다.

대시레인, 똑똑히 들리십니까?

이러한 2FA 인증 요청을 받은 한 대시레인 사용자가 일요일에 도착한 알림 스크린샷을 제공했습니다. 영국에 거주하는 이 사용자는 우려한 나머지 지원 봇을 통해 대시레인에 연락했습니다. 결국 이 사용자는 알림이 전송된 이유에 대해 아무런 정보도 얻지 못했습니다.

이 사용자는 본지에 "그 후 마스토돈(Mastodon) 정보보안 커뮤니티에서 이 소식을 접했지 대시레인으로부터 직접 듣지 못했다"며 "무슨 일이 일어났는지 알아보려고 하는 중입니다! 어떻게 먼저 비밀번호를 훔치지 않고 2FA 요청을 발생시킬 수 있습니까? 유료 고객으로서 저는 마스토돈 정보보안 사람들이 아닌 대시레인으로부터 이 사실을 알았어야 한다고 생각합니다"라고 말했습니다.

수많은 소셜 미디어 논의에서도 이 공격의 기본적인 작동 방식을 이해하지 못하는 다른 사용자들의 비슷한 의견이 쏟아지고 있습니다.

일반적으로 2FA 보호는 인증 앱이나 문자 또는 이메일로 전송되는 일회성 비밀번호(OTP) 형태를 취합니다. 이들은 일반적으로 6자리 숫자로 구성되며 약 45초마다 변경되지만, 위의 알림에서 알 수 있듯이 이 코드는 3시간 동안 유효했습니다.

무차별 대입 공격은 올바른 값을 찾을 때까지 가능한 모든 조합을 빠르게 제출하는 시행착오 방법입니다. 이러한 가정하에 100만 가지의 가능한 비밀번호 조합이 있을 것입니다. 침해에 성공하려면 3시간의 시간 내에 상당한 비율의 조합을 입력해야 합니다. 그렇게 짧은 시간에 그 정도의 추측으로 대시레인 서버를 공격하는 데 필요한 리소스는 동원 가능하지만, 이는 일반적인 무차별 대입 공격에서는 흔히 볼 수 없는 방식입니다.

대시레인은 사용자가 제출할 수 있는 횟수에 속도 제한(rate limit)을 두었다고 명시적으로 밝히지는 않았지만, 권고문에 "사용자 계정에 대한 시도 횟수가 많았기 때문에 대시레인의 보안 통제가 공격을 받은 계정을 자동으로 잠갔다"라는 문구를 볼 때 가능성이 높아 보입니다.

속도 제한이 없었다고 가정하더라도, 1시간 정도에 15만 회 이상의 제출을 받을 때 대시레인 서버가 적어도 일시적으로 멈추지 않을 상상하기 어렵습니다.

대시레인이 언급한 2FA가 다른 것을 의미했을 수도 있습니다. 때때로 2FA는 푸시 알림 형태로 제공되기도 합니다. 누군가 올바른 계정 비밀번호를 입력하면 등록된 기기로 알림이 전송됩니다. 로그인에 성공하려면 사용자는 기기에서 두 번째 인증 요소를 제공하는 버튼을 눌러야 합니다.

2FA 피로 공격(2FA fatigue attack)으로 알려진 전술은 이 과정의 마찰을 악용합니다. 첫 번째 인증 요소를 이미 알아낸 공격자가 반복적으로 로그인을 시도하여 대상에게 푸시 알림을 매번 보냅니다. 수십 번 또는 수백 번의 시도 끝에 대상은 결국 지쳐서 승인 버튼을 누르게 됩니다.

물론 2FA에 대한 무차별 대입 공격은 첫 번째 인증 요소가 이미 뚫렸음을 전제로 합니다. 대시레인은 이 첫 번째 요소가 무엇이며 어떻게 뚫렸는지에 대해 전혀 언급하지 않았습니다.

또 다른 가능성으로는 공격이 대시레인 사용자가 계정에 새로운 기기를 등록할 수 있도록 허용하는 기능을 악용했을 수도 있습니다. 이러한 기술은 일반적으로 사용자를 속여 공격자가 소유한 기기를 승인하도록 요청하는 방식으로 작동합니다.

대시레인은 암호화된 금고를 탈취당한 20명 미만의 계정 보유자에게 연락을 취했다고 밝혔습니다. 회사는 "대시레인 사용자이면서 금고 위험과 관련된 대시레인의 메시지를 받지 못했다면, 해당 사항은 없다"라고 덧붙였습니다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav There’s a lot that doesn’t add up in a security advisory password manager Dashlane published Monday, warning that attackers managed to obtain 20 encrypted user vaults. “Starting on Sunday, May 31, 2026, an external party launched a brute force attack against certain Dashlane user accounts,” the company said . “The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts.” Hello, Dashlane, anybody home? A Dashlane user who received such a 2FA request provided this screenshot of the notification, which arrived on Sunday. The UK-based user was concerned and contacted Dashlane through a support bot. Ultimately the user got no information about why the notification was sent. “Then [I] discovered this news from Mastodon infosec and not Dashlane themselves,” the user told me. “Currently trying to find out what has happened! Because how can you trigger a 2fa request if you haven’t got the password 1st? As a paying customer I think I should have known about this from Dashlane and not Mastodon infosec folks.” Scores of social media discussions are filled with similar comments from users who also don’t understand the basic mechanics of this attack. Typically, 2FA protections take the form of a one-time password generated by an authentication app or sent by text or email. They’re typically six digits long and change every 45 or so seconds, although as the notification above indicates, the code remained valid for three hours. Brute-forcing is a trial-and-error method that rapidly submits every possible combination until landing on the right one. Under these assumptions, there would be 1 million possible passcodes. A successful breach would require a statistically significant percentage of them to be entered within the three-hour window. While the resources needed to bombard Dashlane servers with that volume of guesses in such a short period of time are possible, they’re not commonly found in usual brute-force attacks. Dashlane doesn’t explicitly say it placed a rate limit on the number of submissions a user can make, although it appears likely based on language in the advisory saying “Because of the high volume of attempts on user accounts, Dashlane’s security controls automatically locked accounts that were targeted by the attack.” Even assuming there was no rate limiting, it’s hard to imagine Dashlane servers not at least temporarily choking when receiving 150,000 or more submissions in an hour or so. It’s possible that Dashlane’s reference to 2FA meant something else. Sometimes, 2FA can come in the form of push notifications. Once someone enters the correct account password, the notification is sent to the registered device. For the login to succeed, the user must press a button on their device that provides the second factor. A tactic known as 2FA fatigue attacking exploits the friction of this process. An attacker who has already broken the first authentication factor attempts to log in repeatedly, resulting in a push notification being sent to the target each time. After dozens or even hundreds of attempts, the target finally gives in and presses the approve button. And of course, brute-force attacks on 2FA require the first authentication factor to already have been broken. Dashlane makes no mention of what this factor is or how it was broken. It’s still further plausible that the attack exploited features that allow Dashlane users to enroll new devices in their accounts. Such techniques typically work by tricking the user into approving a request to approve a device owned by the attacker instead. Dashlane said it has contacted fewer than 20 account holders whose encrypted vaults were obtained. “If you’re a Dashlane user and have not received a message from Dashlane specific to vault risk, there is no impact to your Dashlane account,” the company said. It also notes that without the master decryption password—which Dashlane never sees or stores—vault contents remain safe. But without more information, we’re left with more questions than we should be. Dashlane has maintained silence for more than 48 hours since publishing the opaque advisory. Company representatives didn’t respond to an email seeking details. Post updated to add details from a Dashlane user who recived the notifcation. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 15 Comments