Live data from Hacker News

Google uncovers major account-hijacking campaign targeting senior US officials

googleblog.blogspot.com

31–40 of 89 posts

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#31

Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government. The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams. I think a great place for the US govt (a…

I'm sure its no accident that the Pentagon stated they may treat cyber attacks as "acts of war" - http://www.bbc.co.uk/news/world-us-canada-13614125

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#32

Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government. The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams. I think a great place for the US govt (a…

I'd expect the US to be doing the exact same thing to China. I'd be surprised if they weren't.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#33
post #30

Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government. The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams. I think a great place for the US govt (a…

Yeah, it bothers someone: http://www.bbc.co.uk/news/world-us-canada-13614125 Just today it is widely reported the Pentagon is setting a new policy that cyber attacks can be considered acts of war which lets the Pentagon retaliate with conventional weapons. Hack my email, get an ICBM.

Posturing.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#34
post #13
post #6

Does this have anything to do with the backdoor API, or were the passwords just brute forced?

There are no 'backdoor' shenanigans, they comply with subpoenas like everyone else (they uniquely provide a transparency report) the Schneier claim was speculative and he dismissed it later. In this case it's phishing, read the post.

do you know where he dismissed it? the article at http://www.schneier.com/essay-306.html is still up, with no disclaimer or obvious link to a correction.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#35
post #29
post #23

Earlier quoted context omitted.

http://news.ycombinator.com/item?id=2609457

Wrong. A law from 1986 that is being heavily abused ala Patriot Act, allows government to read your email and any other stored data online that is more than 180 days old without any judicial review (aka warrant). This is fact, not speculation. To be fair it's not just gmail but yahoo, etc.

[deleted]

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#36
post #30

Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government. The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams. I think a great place for the US govt (a…

Yeah, it bothers someone: http://www.bbc.co.uk/news/world-us-canada-13614125 Just today it is widely reported the Pentagon is setting a new policy that cyber attacks can be considered acts of war which lets the Pentagon retaliate with conventional weapons. Hack my email, get an ICBM.

I saw this a few days ago. I believe that if another country hacked the US and took top secret data, it could potentially cause as much damage as a conventional weapon. So, using conventional weapons in retaliation for cyber-attacks doesn't seem that far fetched.

We are definitely in an interesting time with regards to technology and policy. Both exciting and scary.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#37
post #29
post #23

Earlier quoted context omitted.

http://news.ycombinator.com/item?id=2609457

Wrong. A law from 1986 that is being heavily abused ala Patriot Act, allows government to read your email and any other stored data online that is more than 180 days old without any judicial review (aka warrant). This is fact, not speculation. To be fair it's not just gmail but yahoo, etc.

Are you referring to the law nicked named the Clinton computer law?

Read it again, any viewing of data on a computer requires notifying accused 180 days after the data view, no exceptions.

As I understand it, the Patriot act replaces that requirement.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#38
post #5

Bad actors take advantage of the fact that most people aren’t that tech savvy—hijacking accounts by using malware and phishing scams that trick users into sharing their passwords, or by using passwords obtained by hacking other websites. Passwords are obsolete. No improvement in storing or transmitting passwords securely will make them easier to remember or less likely to be shared. The approach is fundamentally flaw…

Public key authentication isn't an acceptable alternative? You could have users unlock a keyring using a password containing a single, global public key for each machine they own. You could have them do the same with a thumbdrive or mobile phone. You could authenticate using a number of methods. It's really incrediably flexible. I think the problem is not that there isn't something to replace it, it's that people are…

Practical pubkey verification & authentication requires a repository of public keys. Also, shudder password recovery/reset mechanisms.

I spent a few hours thinking about it once: this isn't much different from the DNS problem.

If a good distributed DNS system can be developed (ie, highly resistant to malicious poisoning), that algorithm can likely transfer to pubkey archives.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#39
post #28
post #18

Earlier quoted context omitted.

I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).

How about 2-factor authentication, as discussed in the article?

SMS is not global and is quite expensive to get started with. Only the major players like Google can roll out worldwide SMS authentication. Email is out of the question because it often takes several minutes to receive an email (due to POP-fetching intervals etc)

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#40
post #13

Earlier quoted context omitted.

There are no 'backdoor' shenanigans, they comply with subpoenas like everyone else (they uniquely provide a transparency report) the Schneier claim was speculative and he dismissed it later. In this case it's phishing, read the post.

do you know where he dismissed it? the article at http://www.schneier.com/essay-306.html is still up, with no disclaimer or obvious link to a correction.

A week or two later on his blog:

http://www.schneier.com/blog/archives/2010/02/more_details_o...

"The rumor that China used a system Google put in place to enable lawful intercepts, which I used as a news hook for this essay, has not been confirmed. At this point, I doubt that it's true."

Post reply on HN