Live data from Hacker News

Hackers Stole My Website

medium.com

91–100 of 144 posts

Re: Hackers Stole My Website

#91

As others have noted, her advice seems to be a little suspect. I took issue with the following: > Your password should not contain “real” words (and definitely not more than one real word in immediate proximity, like “whitecat” or “angrybird”), and should contain capital letters, numbers and symbols. The best passwords of all look like total nonsense. Isn't it generally accepted that the XKCD-style "correct horse bat…

One downside of xkcd style passwords is that they are not accepted everywhere. Many websites have a list of characters you must and must not include in your password.

Re: Hackers Stole My Website

#92

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

I migrated from lastpass to https://www.enpass.io/

It is a cross platform PW manager with Browser extensions (i only use it on macOS with FF and Chromium, though), which does NOT store your passwords in the cloud.

You can sync the database via Cloud storage providers/webdav/usb stick. I really like to be in control of where my passwords are stored.

Sharing of passwords (business usecases!?) is not supported afaik.

Re: Hackers Stole My Website

#93
post #84
post #75

Her password advice is literally the opposite of the classic https://xkcd.com/936/ .

There has been lots of discussion surrounding that comic. I have read a few articles over time and ultimately landed, one way or another, on considering it bad advice. Here is some info from a quick search: https://security.stackexchange.com/questions/6095/xkcd-936-s...

Cool thanks for the link! Were you meaning to say that you consider the "correct horse" password selection principles bad advice? Or that the advice given by the author of the article is bad advice?

Re: Hackers Stole My Website

#94
post #4

>3. Turn off your computer and personal devices when they’re not in use. This article reads like an AOL scare from 1995 directed at my grandma.

> 3. Turn off your computer and personal devices when they’re not in use. Even Bruce Schneier recommends you do that[1]. The idea is that if your machine is a spambot and you don't know it, there are fewer windows of time where your machine can be blasting the Internet with spam. Or if there's some network-based exploit, you're not vulnerable while your device is off. 1. https://www.schneier.com/blog/archives/2004/12…

Except if you have a computer with Intel Management Engine or the AMD equivalent. Then it can be accessed when off. And mobile devices can be turned on remotely as well. You'd have to pull the plug or remove the battery to be truly off but nobody goes through that hassle.

While currently it would take a state actor to do this eventually this will trickle down into to the hackers.

Re: Hackers Stole My Website

#95

It sounds like the core of this hack was an attack on her email (followed by password resets for registrar, etc.). So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own. Stealing email passwords is easy. So easy. No matter ho…

Step #2 is to use unique passwords for your main email addresses. These passwords should be unique in the universe. You must not use them with another account or to encrypt a file etc. Nowhere! And step #3 is to keep all your softwares up to date; OS, antivirus, browser, your WordPress, its plugins, your Notepad++, WinRAR, firmware of your ADSL modem, other computers on the network, BIOS, smart TV etc. Everything sho…

And step #4 is to throw up your hands and shout "Fuck it!" the Nth time you lost everything because you can't find your master copy of your password manager, your back up has drifted out of sync, and you just accidentally spilled your coffee on the flash drive that holds your backup-backup--destroying it.

Hyperbolic sarcasm aside, keeping on top of security is starting to feel like Alice and the Red Queen -- it takes as fast as you can run just to remain in place. I'm starting to feel a bit more sympathy for those who give up on good practices and start using the same password/pin everywhere and pray that ill will never befall them.

Re: Hackers Stole My Website

#96
post #71
post #23

Earlier quoted context omitted.

It's obvious, isn't it? It's here because this is Hacker News and the theft of the website was done by hackers so this is news for our consumption. (an HTML5 compliant tag, since has been repurposed)

Pretty much. I wonder how many people actually read the article.

I found it an interesting story to share with non-techie people about why they need to worry about security.

Also, HN Guidelines ask you not to suggest people haven't read the article. If you don't like the article, flag it or make a constructive comment (which I think you did) and move on.

Re: Hackers Stole My Website

#97
post #75

Her password advice is literally the opposite of the classic https://xkcd.com/936/ .

Whom should I trust?

Well, I am not very well informed on this topic, however, I tend to believe that the math checks out in the "correct horse" principle. This is a vast oversimplification, but basically longer passwords are better - the brute force complexity of additional length is in the exponent, the character diversity (special chars/numbers/upper+lower case) is in the base. Therefore, make your passwords as long (and randomly chosen - i.e. selection method should not be easy to guess!) as you possibly can.

Re: Hackers Stole My Website

#98
post #93
post #84

Earlier quoted context omitted.

There has been lots of discussion surrounding that comic. I have read a few articles over time and ultimately landed, one way or another, on considering it bad advice. Here is some info from a quick search: https://security.stackexchange.com/questions/6095/xkcd-936-s...

Cool thanks for the link! Were you meaning to say that you consider the "correct horse" password selection principles bad advice? Or that the advice given by the author of the article is bad advice?

I feel the "correct horse" method is bad advice. Though, certainly not terrible. I actually followed it for a while and it works amazingly well for memory, but over time I was convinced that the best route is a password manager with randomly generated passwords.

Re: Hackers Stole My Website

#99
post #26

So let me get this straight, her domain got hacked, transferred to a hacker, who proceeded to sell it. Then, she contacted the FBI, who gave her an interview and basically did not much, and then she got her domain back by paying for it and then putting a stop on the money transfer? And this is worthy of a Sandra Bullock movie? Yeah, real nail biter there. This is just content hacking to get me to read more of the art…

Not to mention this was written up by her on mashable back in 2014.... (I commented elsewhere in the thread about it). But yes, I agree completely.

Re: Hackers Stole My Website

#100

It sounds like the core of this hack was an attack on her email (followed by password resets for registrar, etc.). So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own. Stealing email passwords is easy. So easy. No matter ho…

Your preaching but some ears cant hear you. I want to turn on 2FA but I dont know when will that day will come. It also happened to me to loose a smartphone without PIN, and I never thought it would happen and I kept postponing that simple step. Maybe this time I should listen.

2FA isn't hard to use, and is barely inconvenient. How often do you log into your email, anyway?

Also, if you lose your phone, you can make use of your recovery code.

Post reply on HN