Live data from Hacker News

Hackers Stole My Website

medium.com

131–140 of 144 posts

Re: Hackers Stole My Website

#131
post #116

Earlier quoted context omitted.

Is there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.

I use iCloud Keychain. Works well as long as you use safari, which is admittedly uncommon.

Yeah, I tried really hard to make Safari my default browser in order to use keychain. Keychain itself was great, but safari just didn't cut it for me. Their devtools equivalent is terrible, and I didn't like running two browsers. I was bummed to lose keychain, though.

Re: Hackers Stole My Website

#133
post #5

> If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking. So true! A $100 unrooted Android tablet is almost infinitely more secure than the windows/mac, even with the best antivirus. Or if you like physical keyb…

If you want to go down this route, I'd just use qubes os to run each set of apps in its own vm. Sure, you have issues with vm escapes but it's a lot more convenient than switching devices.

Well, qubes requires technical expertise, and a lot of people have a tablet anyway.

My point is, if you want to check online banking, your tablet (ipad|android) is much more secure than your (windows|linux|mac) laptop. For example, here is how I would explain Android security to someone non-technical: "Do not ever enable 'unknown sources' setting, and always refuse if it asks you something about installing a keyboard". Try doing the same for full-featured laptop.

Re: Hackers Stole My Website

#134
post #64

Earlier quoted context omitted.

Except 2fa doesn't work in practice unless you're an expert. See eg gmail: you can't set up 2fa without supplying a cell (you will be allowed to remove it later, but how many know to do this?) Your phone number is trivially stealable -- see eg youtube video of people just stealing phone numbers with a crying baby and a sob story. https://youtu.be/F78UdORll-Q?t=133 Also, lots and lots of places have trivial routes aro…

2FA works in practice against people who don't have physical contact with you. For most people, that's the only threat vector they're worried about. It hardly makes your life more difficult, and it does help at least a little bit. So it's worth setting up.

Not really; sms as 2fa has regularly enabled people to steal accounts they otherwise couldn't have gotten by allowing password resets by stealing your phone number.

See eg @deray getting hacked.

Re: Hackers Stole My Website

#135
post #60

Earlier quoted context omitted.

I'd love to use 1password still, but they have no Linux client (even cli), the web client is long gone, and the Android app is awful. It's really great software, but I don't feel valued as a customer at all.

Web client absolutely exists for subscribers to their syncing service.

Really? That's great news, I only found information about the ancient one that was special-cased in dropbox. I can't even see mention of it on the 1Password website, but as there's a free trial it seems low risk.

Re: Hackers Stole My Website

#136
post #104
post #76

Earlier quoted context omitted.

> EDIT: If you're going to downvote me, did you even read the article? I think the downvotes are because you're accusing the submitter and the people upvoting this article of shilling based on nothing but circumstantial evidence, not because of your opinion on the quality of the linked article.

Fair point on the upvoters, but I still stand by my point on the submitter. Who has the time to submit an article to HN every day?

Quite a lot of people? I mean, I don't myself (because I don't come across enough articles I feel people here wuld be interested in), but it wouldn't be too much of a hassle if I did.

People have time to constantly use Twitter/Facebook/YouTube/Reddit/Tumblr/internet forums in general, they can easily post an article on Hacker News once a day.

Re: Hackers Stole My Website

#137
post #15

And then I called the wire transfer company and placed a stop on the payment. How do you place a stop on a wire transfer? I thought irreversibility was the whole point of wire transfers.

The whole point of wire transfers is traceability. The banks can watch it very closely. I've been able to reverse wire transfers the next day, with a back-date (ie. pretend it never happened). However, author seems to know wire transfers as well as she knows internet security - which is not very well. You can trace the wire into the destination account, but if that person moves it immediately and eventually withdraws…

Yeah, I think there's either missing details regarding the attorneys, etc (which is possible) or this is really "How I Paid $30,000 for My Website." Either way the lack of customer protection from the host and registrar is appalling to me.

Re: Hackers Stole My Website

#138

It sounds like the core of this hack was an attack on her email (followed by password resets for registrar, etc.). So the #1 step to reducing your risk of an attack like this would be setting up 2FA on your email account. The industry standard is password resets via email. If an attacker has access to your email, they have access to every online account you own. Stealing email passwords is easy. So easy. No matter ho…

Your preaching but some ears cant hear you. I want to turn on 2FA but I dont know when will that day will come. It also happened to me to loose a smartphone without PIN, and I never thought it would happen and I kept postponing that simple step. Maybe this time I should listen.

I keep backup codes for my account in two places: My wallet (which I always have on me, so I won't be locked out if I'm traveling), and at home. If you're really paranoid, you could also give backup codes to a friend or relative, or put them in a bank safe or something like that.

Re: Hackers Stole My Website

#139
post #134

Earlier quoted context omitted.

2FA works in practice against people who don't have physical contact with you. For most people, that's the only threat vector they're worried about. It hardly makes your life more difficult, and it does help at least a little bit. So it's worth setting up.

Not really; sms as 2fa has regularly enabled people to steal accounts they otherwise couldn't have gotten by allowing password resets by stealing your phone number. See eg @deray getting hacked.

If a password reset is allowed by pin that's not two factor authentication, that's SINGLE factor authentication. I know we tend to think of 2FA as anything involving a pin sent to your phone, but it does require two factors.

GMail, for instance, will not allow a password reset with just a phone pin.

Re: Hackers Stole My Website

#140
post #56

Earlier quoted context omitted.

Just a data point: 1Password, in the standalone native app version, is the only password manager I recommend.

The other popular one here seems to be keepass. Do you have technical concerns with it, or is it just too user-unfriendly compared to 1Password?

See http://www.infosecisland.com/blogview/21776-KeePass-Vulnerab... and https://www.engadget.com/2016/06/04/keepass-wont-fix-securit...
Post reply on HN