Earlier quoted context omitted.
> If your account was affected, you no longer need to do anything. How do you figure? An unknown actor presumably had full access to your email inbox for a non-zero amount of time and the proper remediation is "nothing"? If I was concerned this had affected me I would right now be changing my passwords to ____everything____.
What attack vector does changing your password help with? Are you concerned they could have recovered the account password via the Oauth scope?
Ask HN: Google Doc email virus?
111–120 of 220 posts
Re: Ask HN: Google Doc email virus?
#112Mailinator here: Yes, we sent the inbox to a blackhole but keep in mind, Mailinator does not and can not actually "Send" any email. It's a receive-only service. As always, any email "from" @mailinator.com has had it's reply-to forged (which is pretty trivial). Also - even before we blackholed the email, it's unlikely any email in that inbox (i.e. hhhh..) was read. Each box has a 50 email limit (FIFO) which was immedi…
> Each box has a 50 email limit (FIFO) which was immediately overwhelmed. That makes me think the malicious author didn't expect this to spread as wide as it did.
http://stackoverflow.com/questions/37321100/how-to-login-wit...
Probably sat in his bedroom right now waiting for the feds going 'wow that escalated quickly'.
Re: Ask HN: Google Doc email virus?
#113I reported this attack vector to Google back in 2012. They awarded a modest bounty, and then a few months later I heard this: > "We're deploying some abuse detection and reactive measures to deal with impostors that might try to abuse this sort of attack. Given this, we do not intend to perform validation that the URL matches the branding information." That last part was in reference to one of my proposed mitigations…
It's sad we can't seem to provide good, usable secure software.
Re: Ask HN: Google Doc email virus?
#114---
Hi Sergio,
It has come to our attention that some of our users may have been hit with a Google Docs phishing scam. It appears that this scam has been spreading throughout the internet today, and is not isolated to Hired or our customers and candidates. If you want more information, you can read about it here or here.
If you receive a Hired email that says that someone from Hired has shared a Google Doc with you, please validate with the sender before clicking the link or doing anything else.
If you think your account may have been compromised, be sure to change your password immediately.
We apologize for this interruption to your day. Please let us know if you have any questions.
Thanks, The Hired team
Re: Ask HN: Google Doc email virus?
#115Re: Ask HN: Google Doc email virus?
#1161) I clicked on the link on my phone's email app. It looked super believable since it was coming from a person I was expecting a Google Doc invite from. I allowed access to "Google Docs" and then the page hit a 502 gateway error.
2) I tried it again on my computer by logging in, and this time, when the page was loading (after I allowed access), I saw the website was not legitimate (based on the url) SO I immediately closed the tab.
Here's the interesting part: None of my contacts got a "Google Docs" invite from me - meaning I didn't "send" any mail. Any idea how I can see if the person behind this has my emails too via API requests?
Re: Ask HN: Google Doc email virus?
#117EDIT: According to a Google representative on the reddit thread, this application is now blocked. If your account was affected, you no longer need to do anything. If you fell for this, changing your password is not the right solution - you want to log into your google account and remove permissions from the application. https://myaccount.google.com/permissions?pli=1 should show a list of apps connected to your accoun…
> If your account was affected, you no longer need to do anything. How do you figure? An unknown actor presumably had full access to your email inbox for a non-zero amount of time and the proper remediation is "nothing"? If I was concerned this had affected me I would right now be changing my passwords to ____everything____.
Re: Ask HN: Google Doc email virus?
#118The very same thing happened at my university. The sender is hhhhhhhhhhhhhhhh@mailinator.com
Re: Ask HN: Google Doc email virus?
#119I reported this attack vector to Google back in 2012. They awarded a modest bounty, and then a few months later I heard this: > "We're deploying some abuse detection and reactive measures to deal with impostors that might try to abuse this sort of attack. Given this, we do not intend to perform validation that the URL matches the branding information." That last part was in reference to one of my proposed mitigations…
Re: Ask HN: Google Doc email virus?
#120The link went to a page that looked like Google Docs and asked for my Google login, but I noticed the domain was wrong so I didn't sign in. I tried the link again today and it looks like Chrome does flag it as a phishing site now.