Live data from Hacker News

Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

bits.blogs.nytimes.com

21–30 of 74 posts

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#21
post #15
post #4

Well actually, looking at the things my parents and parents in law did on their home networks, their Smart TVs and so on, having this in a understandable form for the lay person is really good. To understand, that your door opener, your TV and other things can be "hacked" is important. The information to use different passwords for every service is important. We as people in the know have to help our elders and peers…

Don't trust password managers. They are hackable pieces of software just like the ones you are trying to protect. And they are not reliable (see last news of Lastpass acquisition by LogMeIn). I'm not saying you should ditch password managers and just memorize all of your password. I'm just saying: use them as a well-informed user. Back in the days, Bruce Schneier suggested to write passwords down on a piece of paper…

If someone has access to your local passwordmanager he can also keylog everything you type in. Okay, if he can hack your passwordmanager he gets all of your passwords at the same time. Thats a point.

It matters with one goes faster: Cranking your PW manager or you typing in all your passwords.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#23
post #16
post #12

Fake virus warnings also sucker a lot of older people. Putting them on Chromebooks kills a lot of birds with one stone.

There’s still the possibility of malicious Chrome extensions: I had to eliminate one or two from my son’s Chromebook recently. The naive will always be vulnerable to bad actors unfortunately.

I recommend this extension to find malicious chrome extensions. https://chrome.google.com/webstore/detail/chrome-apps-extens...

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#25
This is a silly article with an alarmist title. They look at a list of sites she likes on Facebook, then they phish her from one of them. Then she lets them into her house where they look for post-it notes with passwords on them. For a grand finale, they open her garage door. I guess the takeaway here is don't let people that identify themselves as "hackers" through your door and into your home office if you have passwords written on post-its, but I am fairly certain this is a rare occurrence.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#26
post #10
post #2

Summary: Hackers send grandmother phishing mail. Grandmother enter her email address and password. Hackers go into house of Grandmother. Hackers change settings on router and and television of grandmother.

Yeah, I don't consider the phishing scams interesting at all. This seems like more of a marketing stunt than anything. And it's borderline not hacking. They actually didn't even do the whole thing themselves. Instead hired a phishing service... To me this is more similar to people dressed as UPS truck drivers going inside an apartment and stealing keys. Or a cashier taking a picture of a customer's credit card. P.S.…

Phishing is hacking. It's social engineering.

They didn't 'hire a phishing service'. They used a website.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#27
post #10
post #2

Summary: Hackers send grandmother phishing mail. Grandmother enter her email address and password. Hackers go into house of Grandmother. Hackers change settings on router and and television of grandmother.

Yeah, I don't consider the phishing scams interesting at all. This seems like more of a marketing stunt than anything. And it's borderline not hacking. They actually didn't even do the whole thing themselves. Instead hired a phishing service... To me this is more similar to people dressed as UPS truck drivers going inside an apartment and stealing keys. Or a cashier taking a picture of a customer's credit card. P.S.…

Social Engineering is absolutely hacking. This wasn't a sophisticated example, but it's still a very real threat.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#28

This is a silly article with an alarmist title. They look at a list of sites she likes on Facebook, then they phish her from one of them. Then she lets them into her house where they look for post-it notes with passwords on them. For a grand finale, they open her garage door. I guess the takeaway here is don't let people that identify themselves as "hackers" through your door and into your home office if you have pas…

The title isn't alarmist. The victim was an ordinary who didn't have a particularly "IoT" home and wasn't a heavy Internet user. They were hacked successfully.

It is a useful article as a warning for non-technical people.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#29

This is a silly article with an alarmist title. They look at a list of sites she likes on Facebook, then they phish her from one of them. Then she lets them into her house where they look for post-it notes with passwords on them. For a grand finale, they open her garage door. I guess the takeaway here is don't let people that identify themselves as "hackers" through your door and into your home office if you have pas…

[deleted]

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#30
post #19

Earlier quoted context omitted.

I want a small hardware, non-connected tablet that acts exclusively as a password manager. It connects to the computer I'm using as a USB keyboard device and only "types" a password when I physically tell it to ("yubikey on steroids"). Backups and system updates via flash card with encrypted filesystem. No wifi, no bluetooth, no phone, no ethernet, no other purpose. Edit: heh, that's funny, you edited your comment as…

Haha, I also thought your comment was a response to what I edited-in about my hardware idea, but yes, we must have been writing it at the same time. When Bitcoin hardware wallets were first getting developed, I wondered why people didn't just start with open, barebones commodity hardware like you've described. Well, I suppose one reason may be that it may not exist, but it seems like it should be pretty cheap to pay…

For radio-free hardware, what about a Palm Pilot? Only has IrDA.
Post reply on HN