Live data from Hacker News

Hackers Stole My Website

medium.com

31–40 of 144 posts

Re: Hackers Stole My Website

#31
post #14
post #9

Earlier quoted context omitted.

And yet many people who were born in 1995 are still using crappy passwords, downloading crappy files from crappy sites with no protection. This stuff may be obvious to us, but it seems we're in a minority.

EDIT: If you're going to downvote me, did you even read the article? Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash - - - But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience? The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking…

I think it is valuable to be reminded of the depth of ignorance of even "tech savvy" people.

Re: Hackers Stole My Website

#32

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

At least in the security circles I'm in, 1Password is the favorite.

KeePassX is recommended sometimes too, but is definitely for the more technically-minded.

There's a low level of distrust for Lastpass.

Re: Hackers Stole My Website

#33
post #14
post #9

Earlier quoted context omitted.

And yet many people who were born in 1995 are still using crappy passwords, downloading crappy files from crappy sites with no protection. This stuff may be obvious to us, but it seems we're in a minority.

EDIT: If you're going to downvote me, did you even read the article? Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash - - - But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience? The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking…

I think the mere fact that they leveraged her email to steal her domain is interesting. You generally don't think of a domain as something people steal

Re: Hackers Stole My Website

#34
As others have noted, her advice seems to be a little suspect. I took issue with the following:

> Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense.

Isn't it generally accepted that the XKCD-style "correct horse battery staple" passwords are more secure?

Re: Hackers Stole My Website

#35

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

PairNIC (https://pairnic.com) now offer TOTP 2FA (use Google Authenticator or whatever else you want).

Re: Hackers Stole My Website

#36
post #14
post #9

Earlier quoted context omitted.

And yet many people who were born in 1995 are still using crappy passwords, downloading crappy files from crappy sites with no protection. This stuff may be obvious to us, but it seems we're in a minority.

EDIT: If you're going to downvote me, did you even read the article? Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash - - - But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience? The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking…

The link to a Traveler's Insurance page with advice to purchase cyber risk insurance (delivered with the same gravity as the advice about changing your passwords) definitely made me ask the same questions. I thought the next line was going to be about X product the author is selling that would prevent this problem for you.

Re: Hackers Stole My Website

#37

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

www.nearlyfreespeech.net (mainly a host but you can register domains with them) offers Google Authenticator 2fa and control over what recovery options are allowed, including none, which is something I wish anyone that supports 2fa would offer.

Re: Hackers Stole My Website

#38

Earlier quoted context omitted.

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

I like keepassx. It just works and no need for any online account. You use a good master key/password and rest of the passwords, don't even remember.

How do you personally handle passwords on multiple devices? Just host it somewhere publicly accessible and use a really strong master?

Re: Hackers Stole My Website

#39

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

name.com offers a choice between Google Authenticator and SMS for 2FA.

Re: Hackers Stole My Website

#40
post #14
post #9

Earlier quoted context omitted.

And yet many people who were born in 1995 are still using crappy passwords, downloading crappy files from crappy sites with no protection. This stuff may be obvious to us, but it seems we're in a minority.

EDIT: If you're going to downvote me, did you even read the article? Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash - - - But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience? The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking…

More like sympathy, I think.
Post reply on HN