Live data from Hacker News

Hackers Stole My Website

medium.com

101–110 of 144 posts

Re: Hackers Stole My Website

#101

Earlier quoted context omitted.

If you simply don't use webmail, you're about 99% less likely to accidentally type your password into a website that happens to look like your webmail login page (which doesn't exist).

Sure. FWIW i avoid using webmail as much as i can, but that's just because i love my mu4e. Still though, i wonder about what would happen in the (admittedly very unlikely) event that someone compromised my secrets file. (example off the top of my head: seized backup disk at border control)

Yeah, depends on what your threat model is. You'll go crazy treating every possible threat as "guaranteed to happen; must defend" though. If you're worried about border control, at least you'll know if they search your stuff and can revoke access after the fact, which puts it in a slightly different category than day to day surreptitious password theft.

Re: Hackers Stole My Website

#102
post #37

Earlier quoted context omitted.

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

www.nearlyfreespeech.net (mainly a host but you can register domains with them) offers Google Authenticator 2fa and control over what recovery options are allowed, including none, which is something I wish anyone that supports 2fa would offer.

Just another happy customer giving those guys a big thumbs-up!

Re: Hackers Stole My Website

#103
post #64

It sounds like the core of this hack was an attack on her email (followed by password resets for registrar, etc.). So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own. Stealing email passwords is easy. So easy. No matter ho…

Except 2fa doesn't work in practice unless you're an expert. See eg gmail: you can't set up 2fa without supplying a cell (you will be allowed to remove it later, but how many know to do this?) Your phone number is trivially stealable -- see eg youtube video of people just stealing phone numbers with a crying baby and a sob story. https://youtu.be/F78UdORll-Q?t=133 Also, lots and lots of places have trivial routes aro…

2FA works in practice against people who don't have physical contact with you. For most people, that's the only threat vector they're worried about.

It hardly makes your life more difficult, and it does help at least a little bit. So it's worth setting up.

Re: Hackers Stole My Website

#104
post #76
post #14

Earlier quoted context omitted.

EDIT: If you're going to downvote me, did you even read the article? Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash - - - But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience? The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking…

> EDIT: If you're going to downvote me, did you even read the article? I think the downvotes are because you're accusing the submitter and the people upvoting this article of shilling based on nothing but circumstantial evidence, not because of your opinion on the quality of the linked article.

Fair point on the upvoters, but I still stand by my point on the submitter. Who has the time to submit an article to HN every day?

Re: Hackers Stole My Website

#105
post #96
post #71

Earlier quoted context omitted.

Pretty much. I wonder how many people actually read the article.

I found it an interesting story to share with non-techie people about why they need to worry about security. Also, HN Guidelines ask you not to suggest people haven't read the article. If you don't like the article, flag it or make a constructive comment (which I think you did) and move on.

Cheers, thanks.

Re: Hackers Stole My Website

#106
post #98
post #93

Earlier quoted context omitted.

Cool thanks for the link! Were you meaning to say that you consider the "correct horse" password selection principles bad advice? Or that the advice given by the author of the article is bad advice?

I feel the "correct horse" method is bad advice. Though, certainly not terrible. I actually followed it for a while and it works amazingly well for memory, but over time I was convinced that the best route is a password manager with randomly generated passwords.

I agree, I think a manager with randomly generated (and long) passwords is the way to go in terms of security + ease of use sweet spot. edit: in addition to 2FA/yubikey type measures.

Re: Hackers Stole My Website

#107
post #12

Earlier quoted context omitted.

I really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.

SMS is far better than nothing. Your average script kiddie is not going to be able to intercept your SMS messages. If you are specifically targeted by sophisticated attackers, maybe.

They'll just social engineer your carrier into the transfer of your phone number to a different SIM card

Re: Hackers Stole My Website

#109
post #64

It sounds like the core of this hack was an attack on her email (followed by password resets for registrar, etc.). So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own. Stealing email passwords is easy. So easy. No matter ho…

Except 2fa doesn't work in practice unless you're an expert. See eg gmail: you can't set up 2fa without supplying a cell (you will be allowed to remove it later, but how many know to do this?) Your phone number is trivially stealable -- see eg youtube video of people just stealing phone numbers with a crying baby and a sob story. https://youtu.be/F78UdORll-Q?t=133 Also, lots and lots of places have trivial routes aro…

I wonder why you cant get a pre-paid at a kiosk. Use a burner phone. Yes, you need some time and effort but if you need good security you will suffer some inconvenience. BTW register the SIM with your spouse or parents name so that there cannot be an easy connection to _any_ of you accounts. Remember also to top-up your prepaid SIM occasionally.

Re: Hackers Stole My Website

#110

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

The article is sparse in details. Which email service did she use? did she get any phishing emails?
Post reply on HN