Bad actors take advantage of the fact that most people aren’t that tech savvy—hijacking accounts by using malware and phishing scams that trick users into sharing their passwords, or by using passwords obtained by hacking other websites. Passwords are obsolete. No improvement in storing or transmitting passwords securely will make them easier to remember or less likely to be shared. The approach is fundamentally flaw…
Google uncovers major account-hijacking campaign targeting senior US officials
11–20 of 89 posts
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#12Re: Google uncovers major account-hijacking campaign targeting senior US officials
#13Does this have anything to do with the backdoor API, or were the passwords just brute forced?
In this case it's phishing, read the post.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#14Re: Google uncovers major account-hijacking campaign targeting senior US officials
#15Why are "Senior US Officials" using gmail?
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#16Earlier quoted context omitted.
Unfortunately, nobody has developed an acceptable alternative In that case they're not really obsolete, are they? Things are obsolete because they're replaced by something better, not because they're imperfect. All you really need to do is to get one of those crypto-card thingies implanted in your brain. Then every time you're prompted for a password you just have to type in the first string of numbers that pops into…
Except those crypto-card thingies (not the implantable ones) were duplicated as a result of the recent RSA breakin, which is how Lockheed was attacked.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#17Nice subtle suggestion.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#18Bad actors take advantage of the fact that most people aren’t that tech savvy—hijacking accounts by using malware and phishing scams that trick users into sharing their passwords, or by using passwords obtained by hacking other websites. Passwords are obsolete. No improvement in storing or transmitting passwords securely will make them easier to remember or less likely to be shared. The approach is fundamentally flaw…
Public key authentication isn't an acceptable alternative? You could have users unlock a keyring using a password containing a single, global public key for each machine they own. You could have them do the same with a thumbdrive or mobile phone. You could authenticate using a number of methods. It's really incrediably flexible. I think the problem is not that there isn't something to replace it, it's that people are…
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#19Re: Google uncovers major account-hijacking campaign targeting senior US officials
#20The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams.
I think a great place for the US govt (and Google) to spend money would be to inform people about phishing and how to detect it. Being a savvy internet user, I sometimes forget that these scams that look ridiculous to me might very well look legitimate to someone else.