Live data from Hacker News

Hackers Stole My Website

medium.com

71–80 of 144 posts

Re: Hackers Stole My Website

#71
post #23
post #14

Earlier quoted context omitted.

EDIT: If you're going to downvote me, did you even read the article? Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash - - - But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience? The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking…

It's obvious, isn't it? It's here because this is Hacker News and the theft of the website was done by hackers so this is news for our consumption. (an HTML5 compliant tag, since has been repurposed)

Pretty much. I wonder how many people actually read the article.

Re: Hackers Stole My Website

#73
post #4

>3. Turn off your computer and personal devices when they’re not in use. This article reads like an AOL scare from 1995 directed at my grandma.

> 3. Turn off your computer and personal devices when they’re not in use. Even Bruce Schneier recommends you do that[1]. The idea is that if your machine is a spambot and you don't know it, there are fewer windows of time where your machine can be blasting the Internet with spam. Or if there's some network-based exploit, you're not vulnerable while your device is off. 1. https://www.schneier.com/blog/archives/2004/12…

> Turn off the computer when you're not using it, especially if you have an "always on" Internet connection.

How old is that article? Sounds like this is from the days back when dial-up was still popular.

I guess there may be some marginal increase in security by turning off your computer like this, but I don't think it's the kind of thing most users should be worried about.

> if your machine is a spambot and you don't know it, there are fewer windows of time where your machine can be blasting the Internet with spam

If your machine is part of a botnet, you're already compromised and turning it off when you're not using it isn't going to fix that. It might marginally help _other_ people getting DDoSed or spammed by your PC, but it won't improve your own security.

> Or if there's some network-based exploit, you're not vulnerable while your device is off

I guess. But unless you become aware of the exploit and take measures to mitigate it before turning your PC on and connecting it to the internet, leaving it off when you're not using it is unlikely to help with this - you'll just be compromised as soon as you turn your PC on. Not to mention that the kind of zero-day that would allow compromising a fully up-to-date PC with nothing more than network access to it is extremely rare.

I'd argue the security benefits of leaving your computer on so it can auto-install security updates while you're away probably outweighs any marginal benefits you might get from turning it off when not using it. (Though either way the difference is extremely minor.)

Re: Hackers Stole My Website

#74
Want to share a strange experience I had: in the year 2014, I was looking for buy a .io domain and was surprised to find that citi.io was available, so I bought it in domains.google.com with an expiration date in 5 years and I also noticed that there was a website called citi.io that I could still visit. I didn't change the DNS settings of the new domain I bought and didn't use the domain.

Then sometime in 2016, I noticed that the domain didn't belong to me. I tried to look up my history of purchase, there was no such purchase record in my account.

Unless my memory fooled me (which I just can't believe), the whole experience made me really confused.

Re: Hackers Stole My Website

#76
post #14
post #9

Earlier quoted context omitted.

And yet many people who were born in 1995 are still using crappy passwords, downloading crappy files from crappy sites with no protection. This stuff may be obvious to us, but it seems we're in a minority.

EDIT: If you're going to downvote me, did you even read the article? Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash - - - But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience? The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking…

> EDIT: If you're going to downvote me, did you even read the article?

I think the downvotes are because you're accusing the submitter and the people upvoting this article of shilling based on nothing but circumstantial evidence, not because of your opinion on the quality of the linked article.

Re: Hackers Stole My Website

#77
I had a boss who had a domain stolen from him too and never got it back. I realize its handy to be able to easily move registrars whenever you want but can we have it more difficult? Eg it would be nice if a registrar would only transfer a domain if it gets a signed letter which it follows up with a phone call then a 3 month delay. With the cut throat competition out there I'd have thought this would be available by now.

After the loss I moved my own domains to google domains which at least has 2fa to access.

Re: Hackers Stole My Website

#78
post #74

Want to share a strange experience I had: in the year 2014, I was looking for buy a .io domain and was surprised to find that citi.io was available, so I bought it in domains.google.com with an expiration date in 5 years and I also noticed that there was a website called citi.io that I could still visit. I didn't change the DNS settings of the new domain I bought and didn't use the domain. Then sometime in 2016, I no…

Maybe you remembered a very vivid dream? The lack of purchase history is a tell that it probably didn't actually happen.

Re: Hackers Stole My Website

#79

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

> > 4. Have antivirus software on your computer

> Only use Windows defender, which is what the security community recommends.

Just don't use windows.

Post reply on HN