Forum use of iubenda.com?

For my own convenience I have a couple of Chrome bookmarks on the bookmarks bar that open the forum either at the list of new posts sorted by number of posts

https://forum.arduino.cc/new?ascending=true&order=posts

or unread posts

https://forum.arduino.cc/unread

This allows quick navigation to posts that I am likely to be interested in and I have used them for the last year or so

Now, all of a sudden, using either of them seems to attempt to log into iubenda.com as the password manager that I use for a limited number of sites pops up a dialogue asking if I want to save the login details, which I don't

The same thing happens when I log off and/or log on or if I simply go to either of the URLs above

I am very suspicious of this activity and have been able to find very little about what iubenda.com does and why

It is perfectly possible that despite precautions my PC has been hit with an infection/malware of some kind, but before taking drastic action does anyone know anything about iubenda.com and its relationship to the Arduino forum, if any ?

Out of interest I have cleared my cookies which had no effect

My password manager has also started to ask me if I want to save a password for iubenda.com (hits1_u) when I click on the bookmark to navigate to the forum.

Environment is Windows 10, Chrome browser, and Last Pass password manger.

When I refresh this page, I see the following related requests:

I think that the culprit may be LastPass

Try turning it off

EDIT : Thinking about it, it is more likely the fact that something is logging into iubenda.com is being revealed by the offer of LastPass to save the details

Now is a good time to switch to a different password manager.

https://www.schneier.com/blog/archives/2022/12/lastpass-breach.html

1 Like

Thanks. I am aware of that breach and have taken action to prevent it affecting me

As I said above, what I believe is happening is that something is logging in to iubenda.com and LastPass is asking if I wish the password to be saved so that the login can be automated

The question is, what is logging in ?

iubenda?

I use NoScript in Firefox and iubenda is blocked; does not seem to effect the functionality of the forum.

Arduino is a logo company on iubenda's website which means money has changed hands and the two have a contract in place. Presumably Arduino is a great customer from iubenda's perspective.

As to the pop-up, knowing what I know about LastPass, my guess is that it's just another LastPass bug.

LastPass is happy and quiet once you save hits1_u as the password for iubenda.com.

Let's see what the LastPass hackers can do with it. :thinking:

What I suspect is happening is that Arduino recently signed up to use iubenda.com and that as a result some actions on the Arduino website cause a login to it.

The LastPass dialogue that pops up is the normal "I can see that you are logging in somewhere and need to supply a password. Would you like me to save the password to automate that process in future ?"

That would explain why agreeing to that would mean that the LastPass dialogue is not seen again

Before agreeing to let LastPass do this I would like to know what the relationship is between Arduino and iuenda.com. As noted by @Coding_Badly, the Arduino logo is featured on the iuenda webpage

so I assume that there is some relationship with them

iubenda has been part of the new (2021) forum website for a very long time; maybe even always. So it's not something recent.

I'm not seeing that. Simple notification POSTs with nothing that looks even remotely like a login attempt.

But, their service is all about regional laws. You being in the UK could trigger different behaviour.

Hi here,

the Arduino website uses Iubenda Privacy and Cookie Policies services to manage the Cookie Policy popup.

The Iubenda script communicates with the Iubenda collector endpoint performing an HTTP POST request containing the user choice. No user data is transmitted over to Iubenda, just the answer on cookie acceptance.
The Iubenda collector endpoint requires HTTP authentication credentials, and it appears that some Password Managers are detecting these credentials and proposing to store those. These credentials are not related to the user account, it's a separate set of credentials just for API communication.

We are going to work with Iubenda to see if the issue with Password Managers can be addressed, but we can ensure that there are no security risks impacting Arduino users.

Regards,
Stefano Visconti
CIO @ Arduino

4 Likes

You are the third employee I spotted here in the forum in the last couple of days.
Things are looking up around here.

Movie gif. Sacha Baron Cohen as Borat gives a man an excited high five with a stiff hand.

@svisconti

Stefano , thank you for the explanation.

By accepting the offer for LastPass to log in the prompt does not appear again, which is what I would expect

Something must have changed recently to make LastPass start prompting but at least the login to iubenda seems legitimate

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.