Live data from Hacker News

Ask HN: Google Doc email virus?

news.ycombinator.com

201–210 of 220 posts

Re: Ask HN: Google Doc email virus?

#201

Mailinator here: Yes, we sent the inbox to a blackhole but keep in mind, Mailinator does not and can not actually "Send" any email. It's a receive-only service. As always, any email "from" @mailinator.com has had it's reply-to forged (which is pretty trivial). Also - even before we blackholed the email, it's unlikely any email in that inbox (i.e. hhhh..) was read. Each box has a 50 email limit (FIFO) which was immedi…

I don't see a TXT record for _dmarc.mailinator.com. If you created a DMARC reject policy all the major webmail providers would block messages "from" mailinator.com

DMARC basically doesn't work, many mailservers don't look at it and those that do frequently ignore the policy -- even setting a REJECT policy typically results in mail being passed through like nothing happened.

Re: Ask HN: Google Doc email virus?

#203
post #176

The bad thing about centralized internet is it makes some mail servers much juicer targets than the decentralized mail servers of old. I decided gmail wasn't for me when I read they harvested your emails for ads. 1GB in 2004 sounded so enticing too! If you are technically savvy and have access to a static IP, I highly recommend setting up postfix/dovecot and registering a domain. It's fairly straight forward for tech…

And then nobody ever receives your mail because the big mail servers don't trust you.

I don't have that problem and my mail PTR doesn't reverse to my mail domain, it reverses to my ISP. Maybe because I have a really old domain.

Re: Ask HN: Google Doc email virus?

#204
post #52

Earlier quoted context omitted.

From the reddit link it looks like Google has fixed it: > Googler here -- I'm escalating to the correct engineering and product teams now. > Edit: This is now resolved. Less than a half-hour after escalation, wow! =) > Final edit: problem is resolved. I clicked the link and got an "oauth client disabled" message. Not pretty, but at least you won't get phished.

"Fixed" in the sense that this app is now blocked. Is there anything to stop an other worm like this, with a different name?

I'm sure they'll do a post-mortem and come up with additional protections, they just take longer than the immediate fix.

Re: Ask HN: Google Doc email virus?

#205

It's a pretty nasty one, since it uses their standard OAuth flow with an app "Google Docs" to have users grant full access to their email and contacts. 1. I can't believe Google doesn't have basic filters to disallow developers from registering an app named "Google Docs" 2. Perhaps there should be some more validation/limits associated with allowing apps on the platform that can gain full access to email. A secure em…

> 1. I can't believe Google doesn't have basic filters to disallow developers from registering an app named "Google Docs" Believe! I think this is just one of the many cases where after the fact everyone is like "oh wow, how didn't they think about it". But that doesn't say you would have thought about this before reading this.

They reportedly knew about this since 2012: https://news.ycombinator.com/item?id=14260298

Re: Ask HN: Google Doc email virus?

#206

Earlier quoted context omitted.

Bravo. Masterclass username for this comment. I'm dying. (For those who may have missed it in this HN crowd, let me momentarily invoke a veil of joke-explainer and offer this http://knowyourmeme.com/memes/hunter2 of the joke.)

Haha, I've been around for a while but that one I missed. Awesome.

HackerNews: Where the subtlety of a comment's humor is inversely proportional to the size of the cognitive DDOS it initiates.

Re: Ask HN: Google Doc email virus?

#207
post #199
post #178

Earlier quoted context omitted.

It was "Google Docs"

I understand that - my question is whether the name is actually a factor that contributed to the spread. As AfroThundr said above, people just want to get to their content and want the dialog to go away. A known contact sends you a document - you're going to trust that and want to see the document. Unless it said the app name was "I'm going to hack your bank account" they'll probably click it (and even then, some wou…

The message was "Google Docs would like to 'Read, send, delete, and mange your email'".

People are way more likely to accept that than if the dialog had been "hhhhhhhhhhh@mailinator.com would like to 'Read, send, delete, and mange your email'".

Re: Ask HN: Google Doc email virus?

#208

Earlier quoted context omitted.

The PCI requirement is to change passwords every 90 days.

And is patently silly, forcing the requirement to decrypt rarely used private keys every 90 days. The requirement should depend on password and hash strength, not some arbitrary decision. PCI does not recommend employing password entropy checkers either. 90 day password can be weak while passing all the requirements.

PCI in general is patently silly.

Re: Ask HN: Google Doc email virus?

#209
post #60

Earlier quoted context omitted.

Heh, they're using Google Analytics to track its spread. That's a nice touch.

It's possible to send any data we want to their Analytics tracker... perhaps we send them some spam?

Where is ilovevitaly when you need him?!

Re: Ask HN: Google Doc email virus?

#210
post #199

Earlier quoted context omitted.

I understand that - my question is whether the name is actually a factor that contributed to the spread. As AfroThundr said above, people just want to get to their content and want the dialog to go away. A known contact sends you a document - you're going to trust that and want to see the document. Unless it said the app name was "I'm going to hack your bank account" they'll probably click it (and even then, some wou…

The message was "Google Docs would like to 'Read, send, delete, and mange your email'". People are way more likely to accept that than if the dialog had been "hhhhhhhhhhh@mailinator.com would like to 'Read, send, delete, and mange your email'".

Trends are moving away from displaying full URLs as well, and while it may look cleaner, I never asked for information to be hidden from me.
Post reply on HN