Live data from Hacker News

Hackers Stole My Website

medium.com

111–120 of 144 posts

Re: Hackers Stole My Website

#111
post #12

Earlier quoted context omitted.

SMS is far better than nothing. Your average script kiddie is not going to be able to intercept your SMS messages. If you are specifically targeted by sophisticated attackers, maybe.

They'll just social engineer your carrier into the transfer of your phone number to a different SIM card

Is it only me who is surprised that in the US no one has the notion of buying pre-paid SIM cards - which are unconnected to your SSN or credit card or bank account?

Re: Hackers Stole My Website

#112
post #17
post #12

Earlier quoted context omitted.

SMS is far better than nothing. Your average script kiddie is not going to be able to intercept your SMS messages. If you are specifically targeted by sophisticated attackers, maybe.

My biggest gripe with SMS 2FA is that it is prone to locking me out of my accounts on travel, if I suddenly need to log in to something and my phone number isn't the same abroad.

[deleted]

Re: Hackers Stole My Website

#113
post #64

Earlier quoted context omitted.

Except 2fa doesn't work in practice unless you're an expert. See eg gmail: you can't set up 2fa without supplying a cell (you will be allowed to remove it later, but how many know to do this?) Your phone number is trivially stealable -- see eg youtube video of people just stealing phone numbers with a crying baby and a sob story. https://youtu.be/F78UdORll-Q?t=133 Also, lots and lots of places have trivial routes aro…

I wonder why you cant get a pre-paid at a kiosk. Use a burner phone. Yes, you need some time and effort but if you need good security you will suffer some inconvenience. BTW register the SIM with your spouse or parents name so that there cannot be an easy connection to _any_ of you accounts. Remember also to top-up your prepaid SIM occasionally.

An non-contracted burner phone in your spouses name that is used to send cryptic looking messages.

That seems like the kind of thing that'd get you on an intelligence agencies watch-list..though these days it's rather hard to find something that wouldn't.

Re: Hackers Stole My Website

#114
post #17
post #12

Earlier quoted context omitted.

SMS is far better than nothing. Your average script kiddie is not going to be able to intercept your SMS messages. If you are specifically targeted by sophisticated attackers, maybe.

My biggest gripe with SMS 2FA is that it is prone to locking me out of my accounts on travel, if I suddenly need to log in to something and my phone number isn't the same abroad.

is it such a pain taking a small burner phone? Alternately, you can install 2FA app in your smartphone. And if you traven that frequently you need to revisit your security choices. There is no security without any efforts from _you_. Google/MS/Apple can only do so much.

Re: Hackers Stole My Website

#115

Earlier quoted context omitted.

At least in the security circles I'm in, 1Password is the favorite. KeePassX is recommended sometimes too, but is definitely for the more technically-minded. There's a low level of distrust for Lastpass.

What about KeePass2?

KeePass is an open-source password manager. There are many compatible programs, many with confusingly-similar names, like KeePassX. KeePass2 is the new version of KeePass, which uses a new file format. Most KeePass-compatible programs, including KeePassX, support the old file format and the new one.

Re: Hackers Stole My Website

#116

> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. Not necessary, use an up to date computer with Win…

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

I use iCloud Keychain. Works well as long as you use safari, which is admittedly uncommon.

Re: Hackers Stole My Website

#117

Earlier quoted context omitted.

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

At least in the security circles I'm in, 1Password is the favorite. KeePassX is recommended sometimes too, but is definitely for the more technically-minded. There's a low level of distrust for Lastpass.

I use KeePassX, no complaints, no 'official' browser extensions not that I'd use one if there where.

Re: Hackers Stole My Website

#118

Earlier quoted context omitted.

Your preaching but some ears cant hear you. I want to turn on 2FA but I dont know when will that day will come. It also happened to me to loose a smartphone without PIN, and I never thought it would happen and I kept postponing that simple step. Maybe this time I should listen.

2FA isn't hard to use, and is barely inconvenient. How often do you log into your email, anyway? Also, if you lose your phone, you can make use of your recovery code.

The reason I mentioned about loosing phone was not related to email recovery but the fact that I did not learn the security lesson of not using a PIN to protect my data.

After I have read this post I wanted to actually enable 2FA right now, but then I discovered that breaking news, terror attack, and again I postponed, the same like I postponed securing my phone with a PIN.

Re: Hackers Stole My Website

#120
post #56

Earlier quoted context omitted.

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

Just a data point: 1Password, in the standalone native app version, is the only password manager I recommend.

The other popular one here seems to be keepass. Do you have technical concerns with it, or is it just too user-unfriendly compared to 1Password?
Post reply on HN