Viewing profile — krebsonsecurity
krebsonsecurity
HN member- Joined
- Sat, Mar 09, 2019, 2:19 PM UTC
- HN karma
- 261
- Public activity
- 40 items
- HN profile
- View on Hacker News ↗
About krebsonsecurity
No profile information was provided.
Recent public activity
-
comment
Comment #49113084
It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT device…
- story
-
comment
Comment #46290618
Sometimes just a little bit DNS research can yield a lot of useful results. Looking at the passive DNS records for the domain chanceletikva.org shows it references the email addres…
-
comment
Comment #40279971
I interviewed some smart people about their research in story published today: https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-...
-
comment
Comment #39991668
Thanks. I did update the story to reflect the apparent fix. I'm still trying to verify if this behavior remains in some form.
-
comment
Comment #39859548
This is the way. You don't have to protect what you don't collect. Mullvad is an excellent example of this. They don't even want you to pick a password, and they're fine if you jus…
-
comment
Comment #39799769
Their earlier statement said they were aware of the CEO's history but were assured that part of his life was behind him. From that statement on March 15: “We were aware of the past…
-
comment
Comment #39746937
It's good to see others coming forward with what they know. Previous discussion on this here: https://news.ycombinator.com/item?id=39709089 Original story: https://krebsonsecurity.…
-
comment
Comment #39374534
Possibly useful info: A list of customer domains affected. https://docs.google.com/spreadsheets/d/1wgKe1VrfNF8Afav1aJtM... One caveat: This list should not be considered exhaustive…
-
comment
Comment #39229362
The identity of the defendant has been doing this for many years and is one of the original members of the Com. The people in that scene sim-swapping artists for their music are th…
-
comment
Comment #38237214
https://www.ftc.gov/legal-library/browse/statutes/fair-credi... IANAL either, but it seems the losses suffered from ID fraud are only recoverable via this.
-
comment
Comment #38164202
Some of the exposure in these cases is due to the fact that you have cybercriminals who've been doing the same things for more than a decade. That is a very long time in which to m…
-
comment
Comment #37933393
Not sure if it's exactly the same thing as what you just mentioned, but I did write recently about criminals using paid Google ads to get their links for popular software downloads…
-
comment
Comment #37400108
I thought about that also, and then one of the victims I talked to brought up a good point. An 8 character password with symbols and numbers doesn't sound like a great password tod…
-
comment
Comment #36227172
This is a fair assumption, although to be fair a botnet is essentially a collection of residential proxies. And yes, Kopeechka controls the inbox, and only lets you see stuff going…
-
comment
Comment #36227125
Thank you for the reminder that I meant to add some of that context in the story (which I will do after finishing this comment). I've written several stories over the years about h…
-
comment
Comment #30879261
This appears to be related. One Github user shared an alert they got today, two days after connecting their Github account to Gitlab. Something about an app added to the account. T…
-
comment
Comment #29717675
The location supplied by the LastPass notification for these login attempt IPs seems off. E.g., just taking some of the IPs most frequently posted here as sources of master passwor…
-
comment
Comment #29582014
That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised rem…
-
comment
Comment #29284638
I agree with your point about not acknowledging these scam attempts. Just wanted to point out the "fight back" bit of the story was advice for people who've already been victimized…
-
comment
Comment #29214754
CF: Would it be asking too much to have a date and time stamp on your blog posts somewhere?
-
comment
Comment #28308763
Yep. And it was worth close to a million on the day he filed this lawsuit.
-
comment
Comment #27911785
There's no probation in the federal system. He will serve the 60 months.
-
comment
Comment #27327153
You are correct. Using the "forgot your password" function on Gmail often reveals snippets of the email account used for recovery and authentication of that account.
-
comment
Comment #27184599
Actually, yes the DarkSide ransomware has a Linux version. See: https://krebsonsecurity.com/wp-content/uploads/2021/05/darks...