Live data from Hacker News

Hackers Stole My Website

medium.com

41–50 of 144 posts

Re: Hackers Stole My Website

#41

It sounds like the core of this hack was an attack on her email (followed by password resets for registrar, etc.). So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own. Stealing email passwords is easy. So easy. No matter ho…

Step #2 is to use unique passwords for your main email addresses. These passwords should be unique in the universe. You must not use them with another account or to encrypt a file etc. Nowhere!

And step #3 is to keep all your softwares up to date; OS, antivirus, browser, your WordPress, its plugins, your Notepad++, WinRAR, firmware of your ADSL modem, other computers on the network, BIOS, smart TV etc. Everything should be updated to the latest version.

Re: Hackers Stole My Website

#42

As others have noted, her advice seems to be a little suspect. I took issue with the following: > Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. Isn't it generally accepted that the XKCD-style "correct horse bat…

You would be correct. The plausibility that algos are geared towards one word/phrase with different variants and small additions are higher than the combination of seemingly random words.

Re: Hackers Stole My Website

#43

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

siteground.com

Re: Hackers Stole My Website

#44

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

See I was all for 2FA, but there were a number of high profile heists that actually used 2FA to gain control first of your mobile number, then email, then anything else they valued. Since mobile operators care even less then hosting companies, I am not sure having 2FA with sms code to be a good security practice.

I do have yubikey keyfob but sites that are supporting it are very few unfortunately. Gmail being one, which is great.

Re: Hackers Stole My Website

#45

Earlier quoted context omitted.

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

At least in the security circles I'm in, 1Password is the favorite. KeePassX is recommended sometimes too, but is definitely for the more technically-minded. There's a low level of distrust for Lastpass.

I'd love to use 1password still, but they have no Linux client (even cli), the web client is long gone, and the Android app is awful.

It's really great software, but I don't feel valued as a customer at all.

Re: Hackers Stole My Website

#46

As others have noted, her advice seems to be a little suspect. I took issue with the following: > Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. Isn't it generally accepted that the XKCD-style "correct horse bat…

As far as I can tell, xkcd passwords are the securest way to generate memorable passwords but it's usually better to use a password manager to generate a random string of characters.

Re: Hackers Stole My Website

#47

It sounds like the core of this hack was an attack on her email (followed by password resets for registrar, etc.). So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own. Stealing email passwords is easy. So easy. No matter ho…

Yeah so about that 2FA. I have a local email client, which uses IMAP and hence cannot do 2FA. What now? I've always thought this is rather a gaping hole. Of course i use app-specific passwords which presumably won't allow access to webmail or changing the account password, but still, if someone got my app password for IMAP, they could still siphon out password reset emails for all my other services.

What do the rest of you do? Only use webmail with 2FA, disable all other access? That seems onerous.

Re: Hackers Stole My Website

#48
post #5

> If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. So true! A $100 unrooted Android tablet is almost infinitely more secure than the windows/mac, even with the best antivirus. Or if you like physical keyb…

If you want to go down this route, I'd just use qubes os to run each set of apps in its own vm. Sure, you have issues with vm escapes but it's a lot more convenient than switching devices.

Re: Hackers Stole My Website

#49

Earlier quoted context omitted.

At least in the security circles I'm in, 1Password is the favorite. KeePassX is recommended sometimes too, but is definitely for the more technically-minded. There's a low level of distrust for Lastpass.

I'd love to use 1password still, but they have no Linux client (even cli), the web client is long gone, and the Android app is awful. It's really great software, but I don't feel valued as a customer at all.

Did they really get rid of the web client? Last I checked they were moving toward the subscription base model and I thought that was more web-centric than the buy-once-and-forget-it version that I'm using.

Re: Hackers Stole My Website

#50

Earlier quoted context omitted.

I like keepassx. It just works and no need for any online account. You use a good master key/password and rest of the passwords, don't even remember.

How do you personally handle passwords on multiple devices? Just host it somewhere publicly accessible and use a really strong master?

I use Tresorit (https://tresorit.com) to sync across machines and phones.
Post reply on HN