Live data from Hacker News

Ask HN: Google warned me that a state organized hacking group targeted me

news.ycombinator.com

31–40 of 43 posts

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#31

Earlier quoted context omitted.

But Google would tell me if they were successful,right? Also: should I tell my coworkers what happened?

If we detected your account was compromised Google would have given you a different notification at that time and forced you to change your password.

Thanks,at least it is something.

I'm really curious what they hoped for though.

I have nothing of interest. I do nothing interesting ( except they get really excited about people working in IT consulting) which probably would be millions by now...

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#32
post #11
post #9

Earlier quoted context omitted.

Not OP but open for a chance. Last time I checked the popular password managers saved the passwords in one way or another. Which personally simply sounds like a bad idea to begin with. Even if in theorie they are safe. Even the slight chance that a single failure could lead to all my passwords getting in the wrong hands at once just is to scary.

Do you have citations for this? AFAIK state of the art is to put the password through some password stretching algorithm (like PKBDF) and to encrypt the database with that. No need to store the password. I think NaCL offers out-of-the-box support for this. EDITED to add: I am using Password Safe which is recommended by Bruce Schneier. What you describe would be an absolute noob mistake. He would be pretty embarrassed…

I think herbst is saying that password managers store the passwords being managed, not the master password used to encrypt the DB.

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#33
post #9

Earlier quoted context omitted.

Not OP but open for a chance. Last time I checked the popular password managers saved the passwords in one way or another. Which personally simply sounds like a bad idea to begin with. Even if in theorie they are safe. Even the slight chance that a single failure could lead to all my passwords getting in the wrong hands at once just is to scary.

They do, but that's not such a bad idea. For an exhaustive read, I wrote this[1] a while back, but I'll try to make the point here too: 1. Are all your passwords unique? 2. If I discovered some of your passwords, will the rest of your passwords stay secure? 3. Were all your passwords created using at least 32 bits of entropy? 4. Are your passwords stored only in encrypted form? 5. Do you perfectly remember every sing…

So, you'll be fine as long as you have a secure passphrase and 2FA :)

And nobody hacks into your machine...

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#34

Earlier quoted context omitted.

If we detected your account was compromised Google would have given you a different notification at that time and forced you to change your password.

Thanks,at least it is something. I'm really curious what they hoped for though. I have nothing of interest. I do nothing interesting ( except they get really excited about people working in IT consulting) which probably would be millions by now...

Do you have any controversial opinions? Have you ever worked for any governments? How about any weapons or other military contractor companies? Critical IT infrastructure? Could be a number of reason's you're targeted.

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#35

Earlier quoted context omitted.

They do, but that's not such a bad idea. For an exhaustive read, I wrote this[1] a while back, but I'll try to make the point here too: 1. Are all your passwords unique? 2. If I discovered some of your passwords, will the rest of your passwords stay secure? 3. Were all your passwords created using at least 32 bits of entropy? 4. Are your passwords stored only in encrypted form? 5. Do you perfectly remember every sing…

So, you'll be fine as long as you have a secure passphrase and 2FA :) And nobody hacks into your machine...

Ofcourse, but at that point it doesn't matter what method of password management you're using. It's too late.

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#36
post #13

Earlier quoted context omitted.

Advanced Persistent Threat (APT aka Nation state) actors are tracked using known indicators of compromise. These indicators can include infrastructure identifiers such as domain names and ip addresses that maybe used in a phishing url or post-compromise for command-and-control or to download other malware. Other indicators can include malware sample hashes or actor-specific detection rules (Example: YARA,Snort or Net…

it doesn’t. i was asking how do they know in this case

The indicators I mentioned are associated with a nation state actor because the attacks in which they were identified were attributed to a nation state. In other words,the selective targeting and sophistication match the interests of a nation state.

Geo-political intelligence analysts and sometimes field officers (aka spies) also play a role. For example,if a specific journalist was attacked while working on an article critical of a specific country and at least one indicator was traced to an a real human associated with that country's spy agency the a confident attribution can be made.

The term "nation state" does sound a bit fancy but it is different from "country" in that many nation states do not act on behalf of their people or to protect the interests of their conuntry. If you use "country" that would include the people of the country while "nation state" simply means the organization running the country. Plus you have situations like taiwan,hong kong and chechnya where those nations are effectively their own nation state but they are under the control of a different country.

Here is a good reference attribution of APT3 (Chinese Ministry of State Security (MSS)): https://threatpost.com/apt3-linked-to-chinese-ministry-of-st...

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#37
post #18
post #9

Earlier quoted context omitted.

Not OP but open for a chance. Last time I checked the popular password managers saved the passwords in one way or another. Which personally simply sounds like a bad idea to begin with. Even if in theorie they are safe. Even the slight chance that a single failure could lead to all my passwords getting in the wrong hands at once just is to scary.

How do you propose one memorizes a properly random/secure/long password, let alone multiple ones, without trusting 'something' with it, whether a password manager of good repute, a hand-rolled version with potentially bigger security issues, or a piece of paper somewhere?

I've memorized multiple long passwords, and routinely memorize new ones. Also phone numbers, poems, mailing addresses, digits of pi, etc. It's not really that challenging. Especially if you do it often.

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#38
post #34

Earlier quoted context omitted.

Thanks,at least it is something. I'm really curious what they hoped for though. I have nothing of interest. I do nothing interesting ( except they get really excited about people working in IT consulting) which probably would be millions by now...

Do you have any controversial opinions? Have you ever worked for any governments? How about any weapons or other military contractor companies? Critical IT infrastructure? Could be a number of reason's you're targeted.

Worked for government, but that is looong ago. Like six years or so? And the government organization I worked is not really interesting I think. ( No weapons, no military, no foreign Relations etc)

Never worked for any military or weapons org or other stuff.

Currently I'm working to create a community portal for a bank. Which will only be used by developers in b2b. ( Documentation and stuff)

But maybe they hoped for weakest link? That's why I'm thinking about to tell my co workers about it.

Re: Ask HN: Google warned me that a state organized hacking group targeted me

#40
Ironic Google warns you of this while we have Apple moving their iCloud to GCBD in China where GCBD is managed by the China Gov.

Then they also moved the keys also to China. Then on top removed the VPN apps from the app store.

Google Gmail was getting hacked by China gov so they warned and ultimately left China.

Even Amnesty International has opened a campaign on Apple and their disregard for privacy.

https://www.amnesty.org/en/latest/news/2018/03/apple-privacy... Campaign targets Apple over privacy betrayal for Chinese iCloud ...

Post reply on HN