Live data from Hacker News

Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

bits.blogs.nytimes.com

61–70 of 74 posts

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#61
post #15

Earlier quoted context omitted.

Don't trust password managers. They are hackable pieces of software just like the ones you are trying to protect. And they are not reliable (see last news of Lastpass acquisition by LogMeIn). I'm not saying you should ditch password managers and just memorize all of your password. I'm just saying: use them as a well-informed user. Back in the days, Bruce Schneier suggested to write passwords down on a piece of paper…

Not all password managers are commercial, closed-source, and cloud-connected. This probably wasn't a main point of yours, but since you mentioned LastPass I felt this should be clarified. I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser. I've been thinking about…

heh, I could build a prototype for $40~$50 or so, maybe we need to start a kickstarter

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#62
post #8
post #3

Earlier quoted context omitted.

Yeah, this isn't really that scary as long as you know how to spot phishing scams. Am disappoint.

A chain is only as strong as its weakest link. If anyone has enough privileges for a malicious attacker to use their account/info to compromise your network then that is the measure of how well protected you are. In this case it was a grandmother, but it doesn't have to be. It could be a salesperson, an HR manager, a burnt out developer. When a business grows to a sufficient size that there are people working in it w…

Yeah, I guess I should be scared that companies I trust might be making these types of mistakes; I hadn't seen it from that angle.

I'm just disappointed that the article was about "hackers" but just talked about scams most of us are already aware of; seems kind of click-baity. They could have entitled the article "Here's One Easy Trick to Protect Yourself from Identity Theft."

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#63
post #14
post #9

"Critical points were that Mrs. Walsh needed a new garage door opener..." I'm surprised they only care about the electronic locks and didn't show how easy it is to pick most of the mechanical locks. Especially when they are talking about the "not hyperconnected" hacks.

Or, you know, break the window, if the garage has a window, or use some other more brute force technique. Less stealthy, but not incredibly different for most purposes.

And with just a roll of duct tape you can silently break a window.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#64
post #51
post #19

Earlier quoted context omitted.

I want a small hardware, non-connected tablet that acts exclusively as a password manager. It connects to the computer I'm using as a USB keyboard device and only "types" a password when I physically tell it to ("yubikey on steroids"). Backups and system updates via flash card with encrypted filesystem. No wifi, no bluetooth, no phone, no ethernet, no other purpose. Edit: heh, that's funny, you edited your comment as…

Hey, I'd be willing to build such a thing. Open source hardware and software and all. Email me at kliment@0xfb.com

heh, I'm interested too, what kinda hardware would you use?

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#65

Earlier quoted context omitted.

I'd disagree, I think is an excellent example of people who think they don't need to worry about security because they aren't on the Internet very much. It was all pretty mundane I agree, right up until they had her power of attorney and social security number. This should be a wake up call to the have-nots: You aren't safe just because you don't post on Facebook and you don't use the computer. Just because you don't…

>It was all pretty mundane I agree, right up until they had her power of attorney and social security number. They only got these after she let them into her house and gave them physical access to her computer . Of course it's only common sense that anyone that is allowed into your home and onto your computer can "pwn" you and worse - hacker or not. That's why 99.9% of people, including this woman, wouldn't allow str…

As I read it, they got that information from her email, and were I a betting man I'd say probably Yahoo or Gmail. They already had her password; getting it from the website would be trivial. This is all my own assumption of course.

The underscore here is that a limited use case person, someone who occasionally posts limited things and doesn't do anything beyond casual ebaying can still be a victim.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#66

Earlier quoted context omitted.

>It was all pretty mundane I agree, right up until they had her power of attorney and social security number. They only got these after she let them into her house and gave them physical access to her computer . Of course it's only common sense that anyone that is allowed into your home and onto your computer can "pwn" you and worse - hacker or not. That's why 99.9% of people, including this woman, wouldn't allow str…

As I read it, they got that information from her email, and were I a betting man I'd say probably Yahoo or Gmail. They already had her password; getting it from the website would be trivial. This is all my own assumption of course. The underscore here is that a limited use case person, someone who occasionally posts limited things and doesn't do anything beyond casual ebaying can still be a victim.

Yes, they got it from email, but they didn't get into the email until they were in the house and got the password from a post-it note for the main account, and the daughter had the browser auto-fill it. They wouldn't have had either of these without a willing participant that let them into the house to find the information. It's like saying "I was easily able to rob the bank vault after the manager opened it".

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#67
post #15

Earlier quoted context omitted.

Don't trust password managers. They are hackable pieces of software just like the ones you are trying to protect. And they are not reliable (see last news of Lastpass acquisition by LogMeIn). I'm not saying you should ditch password managers and just memorize all of your password. I'm just saying: use them as a well-informed user. Back in the days, Bruce Schneier suggested to write passwords down on a piece of paper…

Not all password managers are commercial, closed-source, and cloud-connected. This probably wasn't a main point of yours, but since you mentioned LastPass I felt this should be clarified. I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser. I've been thinking about…

KeePass is also an offline option. It includes the ability for auto type to split data among the clipboard and keyboard. Though I didn't like how wide open it is when unlocked, so I made LockyWindow as an plugin to fix that.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#68
post #50
post #19

Earlier quoted context omitted.

I want a small hardware, non-connected tablet that acts exclusively as a password manager. It connects to the computer I'm using as a USB keyboard device and only "types" a password when I physically tell it to ("yubikey on steroids"). Backups and system updates via flash card with encrypted filesystem. No wifi, no bluetooth, no phone, no ethernet, no other purpose. Edit: heh, that's funny, you edited your comment as…

This exists: https://hackaday.io/project/86-mooltipass

Cool, thanks! It's funny that I and other potential target audience members here, were apparently unaware of this; the internet is a big place. It's a bit too expensive for me, I think -- at least the pre-assembled version. I may steal the smartcard idea, though (or some other form of hardware security.) It might be possible to coerce a phone's SIM slot into serving as an interface to a card.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#69
post #59
post #33

Earlier quoted context omitted.

A couple of them had Bluetooth. The only 68k-based one with builtin Wi-Fi was the AlphaSmart Dana, a writer's keyboard. You're very very unlikely going to want to type a truly secure (= long) password over and over and over, which you'd need to do in a situation where the browser's password manager is turned off, and/or a website disables password caching anyway. The Palm m5xx series could solve this problem: it had…

Just make something like a usb Rubber Ducky with a couple buttons and a screen. Plug it in, scroll to password, hit "type it", and it types it in. Could probably make one for about $40. Arduino Leonardo, LCD Shield, and the leonardo keyboard libraries. Could even have it as a full password generator too.

That actually sounds like a really, really good idea.

Although... I just started thinking about the possibility of using a microcontroller that had a tiny bit of internal, non-reprogrammable ROM, so I could implement a secure stage-0 loader... lol

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#70
post #39
post #33

Earlier quoted context omitted.

A couple of them had Bluetooth. The only 68k-based one with builtin Wi-Fi was the AlphaSmart Dana, a writer's keyboard. You're very very unlikely going to want to type a truly secure (= long) password over and over and over, which you'd need to do in a situation where the browser's password manager is turned off, and/or a website disables password caching anyway. The Palm m5xx series could solve this problem: it had…

> I wonder if I should Ask HN if this would be a good idea. 3. Ask HN ask HN: Should I ask HN if a Palm Pilot keyboard would be a good password manager? 1 point by i336_ 1 minute ago | flag | past | web | discuss

Point taken; that was the wrong way to say it :P

Also, to clarify - and I should've qualified what I meant, but tiredness is such an unhelpful thing at times - this is a genuinely interesting-sounding idea (as I noted to the other reply at this comment depth), but the paragraph at the bottom was kind of an independent thing.

I've always wanted to tinker around with a handheld, reasonably nice-looking device with similar specs to a Palm. Sort of like the TI watch (http://processors.wiki.ti.com/index.php/EZ430-Chronos), but a PDA equivalent.

Post reply on HN