It is great that Google is open with this stuff and the security tips were mostly good, but it was inappropriate to only recommend Chrome in a security message. All modern browsers have anti-phishing features. This came off as advertising.
Google uncovers major account-hijacking campaign targeting senior US officials
21–30 of 89 posts
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#22Unlike TSA gropes, officials cannot legislate themselves out of the backdoor, they might never know when their email is being read, and they did it to themselves.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#23Just imagine what China is doing with the official backdoor gmail is required to have for warrantless searches in the USA. Unlike TSA gropes, officials cannot legislate themselves out of the backdoor, they might never know when their email is being read, and they did it to themselves.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#24Earlier quoted context omitted.
Public key authentication isn't an acceptable alternative? You could have users unlock a keyring using a password containing a single, global public key for each machine they own. You could have them do the same with a thumbdrive or mobile phone. You could authenticate using a number of methods. It's really incrediably flexible. I think the problem is not that there isn't something to replace it, it's that people are…
I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#25Earlier quoted context omitted.
Public key authentication isn't an acceptable alternative? You could have users unlock a keyring using a password containing a single, global public key for each machine they own. You could have them do the same with a thumbdrive or mobile phone. You could authenticate using a number of methods. It's really incrediably flexible. I think the problem is not that there isn't something to replace it, it's that people are…
I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).
If you can't remember a passphrase, the "something you know" portion of "something you know and something you have" is kind of out.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#26Earlier quoted context omitted.
I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).
Other than the current obvious UX deficiencies of installing and using them, a client certificate might help people like your mother-in-law. But one would ideally have a passphrase on their private key. If you can't remember a passphrase, the "something you know" portion of "something you know and something you have" is kind of out.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#27Why are "Senior US Officials" using gmail?
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#28Earlier quoted context omitted.
Public key authentication isn't an acceptable alternative? You could have users unlock a keyring using a password containing a single, global public key for each machine they own. You could have them do the same with a thumbdrive or mobile phone. You could authenticate using a number of methods. It's really incrediably flexible. I think the problem is not that there isn't something to replace it, it's that people are…
I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#29Just imagine what China is doing with the official backdoor gmail is required to have for warrantless searches in the USA. Unlike TSA gropes, officials cannot legislate themselves out of the backdoor, they might never know when their email is being read, and they did it to themselves.
http://news.ycombinator.com/item?id=2609457
A law from 1986 that is being heavily abused ala Patriot Act, allows government to read your email and any other stored data online that is more than 180 days old without any judicial review (aka warrant).
This is fact, not speculation. To be fair it's not just gmail but yahoo, etc.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#30Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government. The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams. I think a great place for the US govt (a…
http://www.bbc.co.uk/news/world-us-canada-13614125
Just today it is widely reported the Pentagon is setting a new policy that cyber attacks can be considered acts of war which lets the Pentagon retaliate with conventional weapons. Hack my email, get an ICBM.