Live data from Hacker News

Google uncovers major account-hijacking campaign targeting senior US officials

googleblog.blogspot.com

21–30 of 89 posts

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#21
post #14

It is great that Google is open with this stuff and the security tips were mostly good, but it was inappropriate to only recommend Chrome in a security message. All modern browsers have anti-phishing features. This came off as advertising.

Unless I'm much mistaken Chrome is the most secure browser out there, so it makes in a video from Google about security imho.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#22
Just imagine what China is doing with the official backdoor gmail is required to have for warrantless searches in the USA.

Unlike TSA gropes, officials cannot legislate themselves out of the backdoor, they might never know when their email is being read, and they did it to themselves.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#23
post #22

Just imagine what China is doing with the official backdoor gmail is required to have for warrantless searches in the USA. Unlike TSA gropes, officials cannot legislate themselves out of the backdoor, they might never know when their email is being read, and they did it to themselves.

http://news.ycombinator.com/item?id=2609457

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#24
post #18

Earlier quoted context omitted.

Public key authentication isn't an acceptable alternative? You could have users unlock a keyring using a password containing a single, global public key for each machine they own. You could have them do the same with a thumbdrive or mobile phone. You could authenticate using a number of methods. It's really incrediably flexible. I think the problem is not that there isn't something to replace it, it's that people are…

I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).

How about adding in another factor of authentication and make the passphrase a hash of data from a biometric scan (e.g. retina scan)?

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#25
post #18

Earlier quoted context omitted.

Public key authentication isn't an acceptable alternative? You could have users unlock a keyring using a password containing a single, global public key for each machine they own. You could have them do the same with a thumbdrive or mobile phone. You could authenticate using a number of methods. It's really incrediably flexible. I think the problem is not that there isn't something to replace it, it's that people are…

I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).

Other than the current obvious UX deficiencies of installing and using them, a client certificate might help people like your mother-in-law. But one would ideally have a passphrase on their private key.

If you can't remember a passphrase, the "something you know" portion of "something you know and something you have" is kind of out.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#26
post #18

Earlier quoted context omitted.

I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).

Other than the current obvious UX deficiencies of installing and using them, a client certificate might help people like your mother-in-law. But one would ideally have a passphrase on their private key. If you can't remember a passphrase, the "something you know" portion of "something you know and something you have" is kind of out.

I'm thinking that he/she was meaning that she can't remember a passphrase so would end up only using a weak password.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#28
post #18

Earlier quoted context omitted.

Public key authentication isn't an acceptable alternative? You could have users unlock a keyring using a password containing a single, global public key for each machine they own. You could have them do the same with a thumbdrive or mobile phone. You could authenticate using a number of methods. It's really incrediably flexible. I think the problem is not that there isn't something to replace it, it's that people are…

I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).

How about 2-factor authentication, as discussed in the article?

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#29
post #23
post #22

Just imagine what China is doing with the official backdoor gmail is required to have for warrantless searches in the USA. Unlike TSA gropes, officials cannot legislate themselves out of the backdoor, they might never know when their email is being read, and they did it to themselves.

http://news.ycombinator.com/item?id=2609457

Wrong.

A law from 1986 that is being heavily abused ala Patriot Act, allows government to read your email and any other stored data online that is more than 180 days old without any judicial review (aka warrant).

This is fact, not speculation. To be fair it's not just gmail but yahoo, etc.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#30

Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government. The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams. I think a great place for the US govt (a…

Yeah, it bothers someone:

http://www.bbc.co.uk/news/world-us-canada-13614125

Just today it is widely reported the Pentagon is setting a new policy that cyber attacks can be considered acts of war which lets the Pentagon retaliate with conventional weapons. Hack my email, get an ICBM.

Post reply on HN