Live data from Hacker News

I was seven words away from being spear-phished

robertheaton.com

71–80 of 187 posts

Re: I was seven words away from being spear-phished

#71

Systematic dropping of definite article makes me suspect the author may be a native speaker of some eastern language with limited knowledge of English.

It’s odd that they would have limited knowledge of English yet understand the prestige of Cambridge, be able to create genuine looking linkedin pages and target the attack so well. If you’re going to that much trouble running a spell checker over he email would seem like a reasonable step?

Most likely it’s a deliberate attempt to target people who are excited enough by the email to not notice the grammar.

Re: I was seven words away from being spear-phished

#72
post #48

This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn'…

I once read a theory that poor grammar, particularly with 419 scams, acts as a sort of gullibility filter where only the most susceptible targets will respond.

I doubt it in this case. It sounds like they had a browser zero-day, and could potentially steal cryptocurrencies from people they were targeting. You don't particularly care how gullible someone is; if you get your zero-day to successfully work on them and steal all their Bitcoin, there's nothing they can do about it.

I think the default assumption is the correct one here; the attacker(s) are a solo or small group of anonymous non-native English speakers, and the risk of getting another person in on it who is a native English speaker wasn't worth it. The smaller your criminal conspiracy, the better.

Re: I was seven words away from being spear-phished

#73
post #35

Earlier quoted context omitted.

A few days ago, I also received the same message from a friend with a link to a fake youtube page, but unlike you, I actually clicked it despite intuitively knowing that it was malicious. Seemed like a "regular" phishing attempt but I now wonder if it is more than that, having read this article.

Probably not a good idea to click a link you know is malicious, you never know what 0-Day they might have

Right. 0-days did not not cross my mind. Until now.

Re: I was seven words away from being spear-phished

#74
I think the real moral of this story is that (like the fun vulnerabilities on Flash and Java that we might remember), a combination of keylogger or strange daemon might be running suddendly on your machine, scanning your files, either on OSX or Windows. Simply visiting a website. So better (as said) is to use a separate VM to access trusted domains (and yes, also VMs aren't these days so trustable). Better to use 2FA and ciphering on-disk sensitive info and loose the habit (if any) of storing a large number of files that streams from locally mounted cloud accounts, like Google file stream, Onedrive files-on-demand and so on.

Re: I was seven words away from being spear-phished

#75
post #60
post #38

I presume that I can I take it from the lack of comment on the Firefox angle that there are no concerns that Firefox is inherently less secure than Chrome?

Chrome had a nasty one back in March, so your presumption seems correct. Really, the best way to protect yourself is to use an obscure OS, or a separate machine for web browsing. Sounds paranoid, but the web is THE main attack vector these days.

Or disable JavaScript, which is the cause of most RCE exploits.

Re: I was seven words away from being spear-phished

#76
> But all it would have taken is for the attackers to add the 7 words “THIS PAGE MUST BE VIEWED IN FIREFOX” to the top of their page, and I’d have been toast.

Unless you were smart and ran the NoScript extension or something similar.

Landing into malicious pages happens; you're not going to avoid it with 100% accuracy and have to be prepared with some sort of countermeasure.

Re: I was seven words away from being spear-phished

#77
post #18

Earlier quoted context omitted.

Elaborate?

"toaster" is pretty common argot for "low-power computer"

After the Power Mac g4 cube came out, that form factor became a trend for a little while.

https://i1.wp.com/www.mac-ave.com/wp-content/uploads/2016/11...

Re: I was seven words away from being spear-phished

#78
The two questions that immediately jumped to my mind on this are

1) does Coinbase's user base skew more towards Firefox than the average, possibly because of perceived better security/privacy and a desire for that among cryptocurrency users?

2) did the zeroday impact Tor browser users, and does Coinbase have a lot of those?

Re: I was seven words away from being spear-phished

#79
post #57

I suppose it's easy to "Monday Morning Quarterback" this one, especially after we now know it's a hoax, but honestly this is more fuel on the fire of: Never respond to random people on the internet asking you for information or to do something. Random people knocking on your door are almost always selling something, and random people contacting you over the Internet are almost always scammers. The story could have en…

That's just really not true. Especially not in a professional setting. I deal with this personally all the time, as the founder of a national conference series. We reach out to people cold all the time and invite them to prominent speaking roles. Sometimes people are surprised to hear from us or don't think of themselves as public speakers but we're most certainly real and serious. I get it the other way all the time…

As is true for most HN posts, I should have prefaced with “In most but not all cases...”

People who do not happen to be conference organizers or frequent recipients of legitimate cold calls should, in most cases, ignore unsolicited messages from strangers.

Re: I was seven words away from being spear-phished

#80
post #44

Earlier quoted context omitted.

.ac.uk emails get spam filtered pretty harshly.

My Alma Mater, The Norwegian University of Technology and Science in Trondheim, Norway had issues with student E-mails being spamhammered all over the world. Why? All student accounts were hosted under stud.ntnu.no; presumably authors of spam filters made other associations when they saw the string 'stud' than it being short for 'student'. Cough. Their practice of automagically generating user names based on parts of…

Their practice of automagically generating user names based on parts of your first and last name in my time led to two users having (for a short time!) the addresses hung@stud.ntnu.no and pervo@stud.ntnu.no.

Brenda Utthead feels their pain.

Post reply on HN