Live data from Hacker News

Google uncovers major account-hijacking campaign targeting senior US officials

googleblog.blogspot.com

11–20 of 89 posts

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#11
post #5

Bad actors take advantage of the fact that most people aren’t that tech savvy—hijacking accounts by using malware and phishing scams that trick users into sharing their passwords, or by using passwords obtained by hacking other websites. Passwords are obsolete. No improvement in storing or transmitting passwords securely will make them easier to remember or less likely to be shared. The approach is fundamentally flaw…

As stated in the article Google already provides 2-step verification as an alternative.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#13
post #6

Does this have anything to do with the backdoor API, or were the passwords just brute forced?

There are no 'backdoor' shenanigans, they comply with subpoenas like everyone else (they uniquely provide a transparency report) the Schneier claim was speculative and he dismissed it later.

In this case it's phishing, read the post.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#16
post #8

Earlier quoted context omitted.

Unfortunately, nobody has developed an acceptable alternative In that case they're not really obsolete, are they? Things are obsolete because they're replaced by something better, not because they're imperfect. All you really need to do is to get one of those crypto-card thingies implanted in your brain. Then every time you're prompted for a password you just have to type in the first string of numbers that pops into…

Except those crypto-card thingies (not the implantable ones) were duplicated as a result of the recent RSA breakin, which is how Lockheed was attacked.

Yeah, I really don't understand how that happened.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#18
post #5

Bad actors take advantage of the fact that most people aren’t that tech savvy—hijacking accounts by using malware and phishing scams that trick users into sharing their passwords, or by using passwords obtained by hacking other websites. Passwords are obsolete. No improvement in storing or transmitting passwords securely will make them easier to remember or less likely to be shared. The approach is fundamentally flaw…

Public key authentication isn't an acceptable alternative? You could have users unlock a keyring using a password containing a single, global public key for each machine they own. You could have them do the same with a thumbdrive or mobile phone. You could authenticate using a number of methods. It's really incrediably flexible. I think the problem is not that there isn't something to replace it, it's that people are…

I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#19
post #3

Obvious sickening propaganda for closing down the Internet!

Why would Google want to close down the Internet?

1. Get tons of cash by being successful & selling bonds 2. Buy up every short call and option on any tech company 3. destroy the Internet 4. Profit!

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#20
Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government.

The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams.

I think a great place for the US govt (and Google) to spend money would be to inform people about phishing and how to detect it. Being a savvy internet user, I sometimes forget that these scams that look ridiculous to me might very well look legitimate to someone else.

Post reply on HN