Live data from Hacker News

Hackers Stole My Website

medium.com

21–30 of 144 posts

Re: Hackers Stole My Website

#22

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

Re: Hackers Stole My Website

#23
post #14
post #9

Earlier quoted context omitted.

And yet many people who were born in 1995 are still using crappy passwords, downloading crappy files from crappy sites with no protection. This stuff may be obvious to us, but it seems we're in a minority.

EDIT: If you're going to downvote me, did you even read the article? Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash - - - But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience? The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking…

It's obvious, isn't it? It's here because this is Hacker News and the theft of the website was done by hackers so this is news for our consumption. (an HTML5 compliant tag, since has been repurposed)

Re: Hackers Stole My Website

#24
post #15

And then I called the wire transfer company and placed a stop on the payment. How do you place a stop on a wire transfer? I thought irreversibility was the whole point of wire transfers.

The whole point of wire transfers is traceability. The banks can watch it very closely. I've been able to reverse wire transfers the next day, with a back-date (ie. pretend it never happened).

However, author seems to know wire transfers as well as she knows internet security - which is not very well. You can trace the wire into the destination account, but if that person moves it immediately and eventually withdraws it out of the banking system, then it's gone. The hacker wouldn't release the domain unless they had control of the funds. I doubt her claims that the hacker doesn't have the money.

Re: Hackers Stole My Website

#25
post #15

And then I called the wire transfer company and placed a stop on the payment. How do you place a stop on a wire transfer? I thought irreversibility was the whole point of wire transfers.

I as well had this thought... I feel like we're not getting all the details on this particular point.

Re: Hackers Stole My Website

#26
So let me get this straight, her domain got hacked, transferred to a hacker, who proceeded to sell it.

Then, she contacted the FBI, who gave her an interview and basically did not much, and then she got her domain back by paying for it and then putting a stop on the money transfer? And this is worthy of a Sandra Bullock movie?

Yeah, real nail biter there.

This is just content hacking to get me to read more of the article so she can make more money on medium. I feel a bit cheated.

Re: Hackers Stole My Website

#27
The most surprising thing is how helpful (and immediate) the FBI was. Wouldn't have guessed that.

Can you really stop a wire transfer? I thought the whole point of wires is that they are immediate and irreversible?

Also, couldn't the FBI track the bank account info back to the thief? Or I guess it's possible the bank account is opened through a stolen identity. I guess the smartest thing the thief could do is then use that money to buy crypto and eventually funnel that back to his real identity.

Re: Hackers Stole My Website

#28
It sounds like the core of this hack was an attack on her email (followed by password resets for registrar, etc.).

So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own.

Stealing email passwords is easy. So easy. No matter how complicated your password is or how often you change it. 2FA is an easy, reliable way to make it orders of magnitude harder for any attacker to breach your account.

I know I'm preaching to the choir here on HN but I'm just flabbergasted this didn't make it into the article.

Re: Hackers Stole My Website

#29

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

I like keepassx. It just works and no need for any online account. You use a good master key/password and rest of the passwords, don't even remember.

Re: Hackers Stole My Website

#30

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

Of my registrars, Namecheap does not but Gandi.net and Hover.com both offer the standard TOTP option.
Post reply on HN