Live data from Hacker News

Google Hack Attack Was Ultra Sophisticated, New Details Show

wired.com

1–10 of 116 posts

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#2
I take this claim with a pinch of salt. It's a neat idea: exploit IE to install a sniffer that picks up Gmail passwords etc. on the local network, but the only "ultra sophisticated" bit of this I can tell is that the hackers did a really good job of covering their tracks.

The article mentions that your average cybercriminal is lazy, and I can believe that - you're only going to put as much time in to an attack that you're going to get out in financial reward. But if a commercial hack was going to bring about the same financial-level of reward, I bet the cybercriminals wouldn't be sloppy.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#3

I take this claim with a pinch of salt. It's a neat idea: exploit IE to install a sniffer that picks up Gmail passwords etc. on the local network, but the only "ultra sophisticated" bit of this I can tell is that the hackers did a really good job of covering their tracks. The article mentions that your average cybercriminal is lazy, and I can believe that - you're only going to put as much time in to an attack that y…

I had a similar train of thought, but in a slightly causality ordering:

Places like google have a high potential for a high payout, and they know it. Therefore the cybersecurity is higher, requiring a better caliber of criminal.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#5

This was ultra sophisticated, they used several layers of multi-encrypted malware to tunnel out and create reverse control channels. Not to mention used a 0day IE bug to install the malware in various targeted companies. This was gov sponsered...

And a team from the People's Liberation Army's signals intelligence branch will find themselves in jail soon for embarrassing the government...

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#7

I take this claim with a pinch of salt. It's a neat idea: exploit IE to install a sniffer that picks up Gmail passwords etc. on the local network, but the only "ultra sophisticated" bit of this I can tell is that the hackers did a really good job of covering their tracks. The article mentions that your average cybercriminal is lazy, and I can believe that - you're only going to put as much time in to an attack that y…

I had a similar train of thought, but in a slightly causality ordering: Places like google have a high potential for a high payout, and they know it. Therefore the cybersecurity is higher, requiring a better caliber of criminal.

"Although the initial attack occurred when company employees visited a malicious web site, Alperovitch said researchers are still trying to determine if this occurred via a URL sent to employees via e-mail or instant messaging or some other method, such as Facebook or other social networking sites."

It still needed an employee to make the usual "install the dancing pigs"-style gaff while using IE6.

Also: Employees using IE6, inside Google, in 2010. Why weren't they using Chrome?

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#8

I take this claim with a pinch of salt. It's a neat idea: exploit IE to install a sniffer that picks up Gmail passwords etc. on the local network, but the only "ultra sophisticated" bit of this I can tell is that the hackers did a really good job of covering their tracks. The article mentions that your average cybercriminal is lazy, and I can believe that - you're only going to put as much time in to an attack that y…

True, it may not have been as ultra-sophisticated as the article lets on, but the fact that there would be no obvious reason to pursue the attack on 34 different companies seems to belie the commercial-hack theory.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#9
post #7

Earlier quoted context omitted.

I had a similar train of thought, but in a slightly causality ordering: Places like google have a high potential for a high payout, and they know it. Therefore the cybersecurity is higher, requiring a better caliber of criminal.

"Although the initial attack occurred when company employees visited a malicious web site, Alperovitch said researchers are still trying to determine if this occurred via a URL sent to employees via e-mail or instant messaging or some other method, such as Facebook or other social networking sites." It still needed an employee to make the usual "install the dancing pigs"-style gaff while using IE6. Also: Employees us…

Also: Employees using IE6, inside Google, in 2010. Why weren't they using Chrome?

I guess they were testing something in IE6. Perhaps one of their own sites. Perhaps how some other site renders in it compared to Chrome. Who knows.

Post reply on HN