Live data from Hacker News

Ask HN: Google warned me that a state organized hacking group targeted me

news.ycombinator.com

11–20 of 43 posts

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#11
post #9

Earlier quoted context omitted.

Absolutely use a password manager, and a strong passphrase for the master password [1] Why would you say not? I'm not trying to be rude or anything. Let's have a discussion, and if I can convince you to do use one, I'd have made one more person safer. [1] I made this for a dead simple way to make passphrases: https://amingilani.github.io/password-maker/

Not OP but open for a chance. Last time I checked the popular password managers saved the passwords in one way or another. Which personally simply sounds like a bad idea to begin with. Even if in theorie they are safe. Even the slight chance that a single failure could lead to all my passwords getting in the wrong hands at once just is to scary.

Do you have citations for this? AFAIK state of the art is to put the password through some password stretching algorithm (like PKBDF) and to encrypt the database with that. No need to store the password. I think NaCL offers out-of-the-box support for this.

EDITED to add: I am using Password Safe which is recommended by Bruce Schneier. What you describe would be an absolute noob mistake. He would be pretty embarrassed if you were right.

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#13

how do they know it’s a state organized group?

Advanced Persistent Threat (APT aka Nation state) actors are tracked using known indicators of compromise. These indicators can include infrastructure identifiers such as domain names and ip addresses that maybe used in a phishing url or post-compromise for command-and-control or to download other malware.

Other indicators can include malware sample hashes or actor-specific detection rules (Example: YARA,Snort or Netwitness rules).

These indicators are typically not public. Some can be accessed if you pay the right sum of money and undergo vetting,still,some are kept private within the relevat security firms or organizations.

As you can imagine,Google has their hands in many pies including security research and threat intelligence collection(Everyone loves their VirusTotal intelligence product). They can scan email metadata for any of these indicators as they see fit.

Generally speaking,some indicators are of such high quality, they can be used to detect well crafted spear phishing by a nation state actor. But most are good only to detect untargeted attacks or targeted attacks that include a large number of targets.

Hope that answered your question.

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#14
post #13

how do they know it’s a state organized group?

Advanced Persistent Threat (APT aka Nation state) actors are tracked using known indicators of compromise. These indicators can include infrastructure identifiers such as domain names and ip addresses that maybe used in a phishing url or post-compromise for command-and-control or to download other malware. Other indicators can include malware sample hashes or actor-specific detection rules (Example: YARA,Snort or Net…

it doesn’t. i was asking how do they know in this case

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#15
post #13

how do they know it’s a state organized group?

Advanced Persistent Threat (APT aka Nation state) actors are tracked using known indicators of compromise. These indicators can include infrastructure identifiers such as domain names and ip addresses that maybe used in a phishing url or post-compromise for command-and-control or to download other malware. Other indicators can include malware sample hashes or actor-specific detection rules (Example: YARA,Snort or Net…

also why do people like to use the term nation state when it involves hacking. just to sound fancier? according to wiki nation state has a precise meaning and it’s not equivalent to the term country

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#16

This is when you know you've "made it", when state intel is trying to get to you :-) Seriously now, even though you're not famous or a jounalist you might have some type of valuable access in your life? Or maybe it's just a false positive from google. Or maybe you weren't being especially targetted, and instead your e-mail ended up in some list of valuable e-mails (rightly or wrongly).

Yeah but they’re not going to let you know if the NSA or the CIA targets you.

So the message can be read more like: a non-allied state actor has targeted your email and we are notifying you to show how good we are. Please note we will not reveal when you are targeted by an allied state intelligence. Privacy is relative, mostly an illusion. Thank you for your cooperation.

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#17

This in itself sounds like a phishing attack. Is the mail authentic?

Not a mail.you get that message when logging in to Google. I first thought that too.and tried another browser ( got that message in Vivaldi first,than tried IE) Same result. Here are some old articles about that: https://www.recode.net/2017/3/24/15054954/google-reassures-u... http://www.zdnet.com/article/google-heres-why-you-shouldnt-f...

interesting. does anyone know how ProtonMail handles such situations and whether they alert their users?

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#18
post #9

Earlier quoted context omitted.

Absolutely use a password manager, and a strong passphrase for the master password [1] Why would you say not? I'm not trying to be rude or anything. Let's have a discussion, and if I can convince you to do use one, I'd have made one more person safer. [1] I made this for a dead simple way to make passphrases: https://amingilani.github.io/password-maker/

Not OP but open for a chance. Last time I checked the popular password managers saved the passwords in one way or another. Which personally simply sounds like a bad idea to begin with. Even if in theorie they are safe. Even the slight chance that a single failure could lead to all my passwords getting in the wrong hands at once just is to scary.

How do you propose one memorizes a properly random/secure/long password, let alone multiple ones, without trusting 'something' with it, whether a password manager of good repute, a hand-rolled version with potentially bigger security issues, or a piece of paper somewhere?

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#19

Earlier quoted context omitted.

What ! Don’t use a password manager and turn on 2 factor Authentication

Absolutely use a password manager, and a strong passphrase for the master password [1] Why would you say not? I'm not trying to be rude or anything. Let's have a discussion, and if I can convince you to do use one, I'd have made one more person safer. [1] I made this for a dead simple way to make passphrases: https://amingilani.github.io/password-maker/

Not parent but I'm guessing the rationale is that a password manager could undermine the concept of 2fa.

Some believe that the "something you know" should be stored inside your head. I personally use a password manager, but can understand the viewpoint.

Password managers lie somewhere between 2 different factors, "have" (the password DB) and "know" (only your master password). For those who use a laptop as their 2nd factor (yubikey plugged into a USB port, a token on the system itself) and get their laptop stolen, a compromise of the password safe could result in both factors being breached.

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#20
post #13

Earlier quoted context omitted.

Advanced Persistent Threat (APT aka Nation state) actors are tracked using known indicators of compromise. These indicators can include infrastructure identifiers such as domain names and ip addresses that maybe used in a phishing url or post-compromise for command-and-control or to download other malware. Other indicators can include malware sample hashes or actor-specific detection rules (Example: YARA,Snort or Net…

also why do people like to use the term nation state when it involves hacking. just to sound fancier? according to wiki nation state has a precise meaning and it’s not equivalent to the term country

I think it's probably due to the fact that when the phrasing became popular, China was almost exclusively the focus. So itay not be accurate now, but at this point it's a habit.
Post reply on HN