Live data from Hacker News

Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

bits.blogs.nytimes.com

11–20 of 74 posts

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#11
post #2

Summary: Hackers send grandmother phishing mail. Grandmother enter her email address and password. Hackers go into house of Grandmother. Hackers change settings on router and and television of grandmother.

curious, is this really a bot or someone just providing a service under the guise of a bot? be pretty cool if it was the former. that would be some serious natural language processing. (not that i know anything about that subject) i read the article, this post does seem like a pretty accurate summary.

Its difficult for one person to judge that. Some kind of bias creeps in when you read the article and see the summary again since your mind fills the gap automatically which is created by the summary.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#13
>> To spare Mrs. Walsh any actual harm, the hackers used a service called Phish5, which does not actually store passwords and is often used by employers to test employees’ ability to spot malicious phishing cons.

I'm signing up for Phish5. Looks like exactly what I need for my team.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#14
post #9

"Critical points were that Mrs. Walsh needed a new garage door opener..." I'm surprised they only care about the electronic locks and didn't show how easy it is to pick most of the mechanical locks. Especially when they are talking about the "not hyperconnected" hacks.

Or, you know, break the window, if the garage has a window, or use some other more brute force technique. Less stealthy, but not incredibly different for most purposes.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#15
post #4

Well actually, looking at the things my parents and parents in law did on their home networks, their Smart TVs and so on, having this in a understandable form for the lay person is really good. To understand, that your door opener, your TV and other things can be "hacked" is important. The information to use different passwords for every service is important. We as people in the know have to help our elders and peers…

Don't trust password managers. They are hackable pieces of software just like the ones you are trying to protect. And they are not reliable (see last news of Lastpass acquisition by LogMeIn).

I'm not saying you should ditch password managers and just memorize all of your password. I'm just saying: use them as a well-informed user.

Back in the days, Bruce Schneier suggested to write passwords down on a piece of paper and keep it in your wallet as the least weak security measure. Today, based on this article[0], he actually recommends the use of a password manager "[...] simply because it allows you to choose longer and stronger passwords.", which basically means it's the lesser of two evils.

[0] https://www.schneier.com/blog/archives/2014/09/security_of_p...

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#16
post #12

Fake virus warnings also sucker a lot of older people. Putting them on Chromebooks kills a lot of birds with one stone.

There’s still the possibility of malicious Chrome extensions: I had to eliminate one or two from my son’s Chromebook recently. The naive will always be vulnerable to bad actors unfortunately.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#17
post #15
post #4

Well actually, looking at the things my parents and parents in law did on their home networks, their Smart TVs and so on, having this in a understandable form for the lay person is really good. To understand, that your door opener, your TV and other things can be "hacked" is important. The information to use different passwords for every service is important. We as people in the know have to help our elders and peers…

Don't trust password managers. They are hackable pieces of software just like the ones you are trying to protect. And they are not reliable (see last news of Lastpass acquisition by LogMeIn). I'm not saying you should ditch password managers and just memorize all of your password. I'm just saying: use them as a well-informed user. Back in the days, Bruce Schneier suggested to write passwords down on a piece of paper…

Not all password managers are commercial, closed-source, and cloud-connected. This probably wasn't a main point of yours, but since you mentioned LastPass I felt this should be clarified.

I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser.

I've been thinking about converting an old Android device into a more secure password manager. I envision having the device hold the decryption key for the PW "vault" as long as it's connected to my authenticated system. I either request credentials from the PC and approve on-device, or select them on the screen, and it types them as a USB keyboard (or perhaps some other way less prone to garden-variety keyloggers.) I guess I haven't because it's kind of a lot of effort and will lower convenience levels. :)

I ought to at least find a better way than the clipboard, to transfer passwords from the manager app to the browser etc...

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#18
post #15
post #4

Well actually, looking at the things my parents and parents in law did on their home networks, their Smart TVs and so on, having this in a understandable form for the lay person is really good. To understand, that your door opener, your TV and other things can be "hacked" is important. The information to use different passwords for every service is important. We as people in the know have to help our elders and peers…

Don't trust password managers. They are hackable pieces of software just like the ones you are trying to protect. And they are not reliable (see last news of Lastpass acquisition by LogMeIn). I'm not saying you should ditch password managers and just memorize all of your password. I'm just saying: use them as a well-informed user. Back in the days, Bruce Schneier suggested to write passwords down on a piece of paper…

[deleted]

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#19
post #15

Earlier quoted context omitted.

Don't trust password managers. They are hackable pieces of software just like the ones you are trying to protect. And they are not reliable (see last news of Lastpass acquisition by LogMeIn). I'm not saying you should ditch password managers and just memorize all of your password. I'm just saying: use them as a well-informed user. Back in the days, Bruce Schneier suggested to write passwords down on a piece of paper…

Not all password managers are commercial, closed-source, and cloud-connected. This probably wasn't a main point of yours, but since you mentioned LastPass I felt this should be clarified. I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser. I've been thinking about…

I want a small hardware, non-connected tablet that acts exclusively as a password manager. It connects to the computer I'm using as a USB keyboard device and only "types" a password when I physically tell it to ("yubikey on steroids"). Backups and system updates via flash card with encrypted filesystem. No wifi, no bluetooth, no phone, no ethernet, no other purpose.

Edit: heh, that's funny, you edited your comment as I was replying? Now we just need someone to build it for us :)

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#20
post #19

Earlier quoted context omitted.

Not all password managers are commercial, closed-source, and cloud-connected. This probably wasn't a main point of yours, but since you mentioned LastPass I felt this should be clarified. I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser. I've been thinking about…

I want a small hardware, non-connected tablet that acts exclusively as a password manager. It connects to the computer I'm using as a USB keyboard device and only "types" a password when I physically tell it to ("yubikey on steroids"). Backups and system updates via flash card with encrypted filesystem. No wifi, no bluetooth, no phone, no ethernet, no other purpose. Edit: heh, that's funny, you edited your comment as…

Haha, I also thought your comment was a response to what I edited-in about my hardware idea, but yes, we must have been writing it at the same time.

When Bitcoin hardware wallets were first getting developed, I wondered why people didn't just start with open, barebones commodity hardware like you've described. Well, I suppose one reason may be that it may not exist, but it seems like it should be pretty cheap to pay some low-end Android manufacturer to remove a few features from their design. Or maybe you even buy "normal" hardware and strip out radios. At some level, the wallet manufacturers are all trusting someone, as I don't think any have designed their own low-level components. Anyway, maybe I will revisit that idea to see if a suitable locked-down, easy-to-hack, super-cheap device is available, as I agree that cutting all unnecessary comms is a good idea.

Post reply on HN