Live data from Hacker News

I was seven words away from being spear-phished

robertheaton.com

61–70 of 187 posts

Re: I was seven words away from being spear-phished

#61
post #38

I presume that I can I take it from the lack of comment on the Firefox angle that there are no concerns that Firefox is inherently less secure than Chrome?

Previous discussion about the zero-day itself: https://news.ycombinator.com/item?id=20233952

Browsers have zero-days sometimes; this is a valid question worth asking, but for now I wouldn't tell anyone to ditch Firefox over this, any more than I would tell someone to ditch MacOS over this.

Re: I was seven words away from being spear-phished

#62
post #18

Earlier quoted context omitted.

Elaborate?

"toaster" is pretty common argot for "low-power computer"

I have a white EeePC 901. While I was still using it as my carry-around laptop, it was called "Toastie", because it looked kind of like a sandwich toaster.

Re: I was seven words away from being spear-phished

#63
post #38

I presume that I can I take it from the lack of comment on the Firefox angle that there are no concerns that Firefox is inherently less secure than Chrome?

How common are browser 0-days? It seems like everyone makes mistakes. Eg Chrome patched CVE-2019-5786 last month.

Re: I was seven words away from being spear-phished

#64
post #60
post #38

I presume that I can I take it from the lack of comment on the Firefox angle that there are no concerns that Firefox is inherently less secure than Chrome?

Chrome had a nasty one back in March, so your presumption seems correct. Really, the best way to protect yourself is to use an obscure OS, or a separate machine for web browsing. Sounds paranoid, but the web is THE main attack vector these days.

There are disadvantages to using an obscure OS too, in that it is likely slower to get security fixes, and may have more security flaws.

Re: I was seven words away from being spear-phished

#66
post #57

I suppose it's easy to "Monday Morning Quarterback" this one, especially after we now know it's a hoax, but honestly this is more fuel on the fire of: Never respond to random people on the internet asking you for information or to do something. Random people knocking on your door are almost always selling something, and random people contacting you over the Internet are almost always scammers. The story could have en…

That's just really not true. Especially not in a professional setting. I deal with this personally all the time, as the founder of a national conference series. We reach out to people cold all the time and invite them to prominent speaking roles. Sometimes people are surprised to hear from us or don't think of themselves as public speakers but we're most certainly real and serious. I get it the other way all the time…

Yeah, so I have published a few journal articles. Nary a day goes by without receiving multiple emails begging for me to speak at a conference (invariably in China), or submit another article to their particular journal (that I have never heard of before). So, you can understand why cold introduction emails tend to get redirected to /dev/null.

Re: I was seven words away from being spear-phished

#67

> Neil describes his pre-university education as “High School”. We don’t have “High School” in the UK - we call it “Secondary School”. This might make sense if Neil was American, or trying to communicate with an American audience, but there’s no indication that this is the case. Many secondary schools in the UK still have "High School" in their name. I've always used the two terms interchangeably, but maybe that's be…

This particular school (the Perse, in Cambridge) calls its secondary section the "Upper School". It's also quite expensive.

Re: I was seven words away from being spear-phished

#68
post #35
post #26

It's impossible to overestimate the power of expectations to create trust (even in the face of contrary indications). This just almost happened to me this week: A couple of days ago I wrote an email to a friend I hadn't been in touch with for several years. A day later I got a message from him on Facebook with what looked like a YouTube link and the cryptic message, "It's you?" I didn't want to see myself on a random…

A few days ago, I also received the same message from a friend with a link to a fake youtube page, but unlike you, I actually clicked it despite intuitively knowing that it was malicious. Seemed like a "regular" phishing attempt but I now wonder if it is more than that, having read this article.

Probably not a good idea to click a link you know is malicious, you never know what 0-Day they might have

Re: I was seven words away from being spear-phished

#69
post #60
post #38

I presume that I can I take it from the lack of comment on the Firefox angle that there are no concerns that Firefox is inherently less secure than Chrome?

Chrome had a nasty one back in March, so your presumption seems correct. Really, the best way to protect yourself is to use an obscure OS, or a separate machine for web browsing. Sounds paranoid, but the web is THE main attack vector these days.

You could use Qubes OS[0] which will allow you to isolate different aspects of your computing into separate VMs easily.

[0] https://www.qubes-os.org/

Re: I was seven words away from being spear-phished

#70
post #60

Earlier quoted context omitted.

Chrome had a nasty one back in March, so your presumption seems correct. Really, the best way to protect yourself is to use an obscure OS, or a separate machine for web browsing. Sounds paranoid, but the web is THE main attack vector these days.

There are disadvantages to using an obscure OS too, in that it is likely slower to get security fixes, and may have more security flaws.

The only logical answer is to write your own OS

The ultimate security by obscurity

Post reply on HN