Live data from Hacker News

I was seven words away from being spear-phished

robertheaton.com

41–50 of 187 posts

Re: I was seven words away from being spear-phished

#41
post #26

It's impossible to overestimate the power of expectations to create trust (even in the face of contrary indications). This just almost happened to me this week: A couple of days ago I wrote an email to a friend I hadn't been in touch with for several years. A day later I got a message from him on Facebook with what looked like a YouTube link and the cryptic message, "It's you?" I didn't want to see myself on a random…

Okay but let's be clear. Clicking a link won't steal your information.

Going to a bad link and giving your details is how you are phished.

Re: I was seven words away from being spear-phished

#42

The specifics of this - the request to judge a prize one is clearly unqualified for - are we as software engineers particularly vulnerable to? Most people would, I think, conclude "this is fake, because why would I be asked to do this?". But I often think that as software engineers we fancy ourselves to have more insight into other fields than we really do. Does this ring true to anyone else?

They were targeting cryptocurrency people, not software engineers. And cryptocurrency people very often have an immensely inflated opinion of their own knowledge of economics, so it's actually absolutely perfect bait.

Re: I was seven words away from being spear-phished

#43
post #39

Earlier quoted context omitted.

I've heard of at least one case where money was transferred out of someone's bank account through online banking and he was held liable. The user claimed fraud but since the intruder used his username and password the bank refused to refund the money claiming he had a responsibility to secure his username and password.

>since the intruder used his username and password the bank refused to refund the money claiming he had a responsibility to secure his username and password what jurisdiction is this? this seems like the worse consumer protection law ever.

It was definitely the U.S. I want to say Maine, but my memory is fuzzy.

Re: I was seven words away from being spear-phished

#44
post #5

Earlier quoted context omitted.

It also means the e-mail is significantly more likely to make it past a spam filter, even an aggressive one. There was very little in that e-mail any reasonable spam filter could possibly have flagged, unless they're going to start doing API calls to grammarly. But if they check spelling and grammar, filters will start flagging a lot more than spam.

.ac.uk emails get spam filtered pretty harshly.

My Alma Mater, The Norwegian University of Technology and Science in Trondheim, Norway had issues with student E-mails being spamhammered all over the world.

Why? All student accounts were hosted under stud.ntnu.no; presumably authors of spam filters made other associations when they saw the string 'stud' than it being short for 'student'.

Cough. Their practice of automagically generating user names based on parts of your first and last name in my time led to two users having (for a short time!) the addresses hung@stud.ntnu.no and pervo@stud.ntnu.no.

Re: I was seven words away from being spear-phished

#45

This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn'…

I read in the past that this was intentional - it's a filter to ensure that people who are inclined to note detail pass up on the offer, meaning they only get the most likely prospects to be ripped off.

That’s likely true for the Nigerian prince scammers, but when they’ve got a browser zero day, they can successfully attack people that aren’t suckers.

Re: I was seven words away from being spear-phished

#47
post #26

It's impossible to overestimate the power of expectations to create trust (even in the face of contrary indications). This just almost happened to me this week: A couple of days ago I wrote an email to a friend I hadn't been in touch with for several years. A day later I got a message from him on Facebook with what looked like a YouTube link and the cryptic message, "It's you?" I didn't want to see myself on a random…

Okay but let's be clear. Clicking a link won't steal your information. Going to a bad link and giving your details is how you are phished.

If that link has browser 0day, it can. If that link takes you to a page you expect to demand login creds (google groups, youtube, google docs), it can.

Re: I was seven words away from being spear-phished

#48

This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn'…

I once read a theory that poor grammar, particularly with 419 scams, acts as a sort of gullibility filter where only the most susceptible targets will respond.

Re: I was seven words away from being spear-phished

#49
post #17

Earlier quoted context omitted.

AFAIK spear phishing refers to the fact that the attack is tailored/targeted, rather than mass mailings.

The "spear" means it's targeted, but it's still "phishing" - meaning the attack vector is a cloned version of a legit page I guess this should be called spear-hacking?

This seems to fit the classic definition of spearphishing; the atack vector is an impersonated/fake version of a legit email and its sender. No matter if the payload is in the form of an attachment or web link or a request for some physical action (e.g. please scan and send a copy of your ID) that would fit the phishing title.

Re: I was seven words away from being spear-phished

#50
post #45

Earlier quoted context omitted.

I read in the past that this was intentional - it's a filter to ensure that people who are inclined to note detail pass up on the offer, meaning they only get the most likely prospects to be ripped off.

That’s likely true for the Nigerian prince scammers, but when they’ve got a browser zero day, they can successfully attack people that aren’t suckers.

True, but we don't know the next stage of their attack. Perhaps after compromising the target's machine the attackers would have to then engage in some social engineering.
Post reply on HN