Live data from Hacker News

Google uncovers major account-hijacking campaign targeting senior US officials

googleblog.blogspot.com

71–80 of 89 posts

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#71
post #58
post #53

Earlier quoted context omitted.

Unfortunately, after seeing the firewall logs of several Internet facing machines in distinct hosting providers in different parts of the world, it's quite interesting to notice that 90% if not more of the port scans, http vulnerability scans, among others, come from network blocks from that part of the planet. Even more illuminating that if their great firewall is so advanced, being able to block anything on a need…

My understanding was the great firewall isn't so advanced. It is essentially a filter system, run in quite a manual fashion (i.e eyeballs on screens assessing if things should be blocked). I'm not refuting attacks originating from china, there is piles of evidence that support this. Things to keep in mind - there are more internet users in china, than anywhere else, so there is going to be more of 'everything' from c…

Very well said. In fact, blind nationalism is the very same strategy the 50-cent party uses (referring to the parent comment).

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#72
Google should consider adding an option to lock your account access based on IP range or even a geo-located area based on IP address. There are some challenges to geo-locating IPs, and this wouldn't stop a determined hacker, but it could foil a significant number of attacks.

They also might want to provide some reporting for users to know when their account was accessed or attempted to be accessed and from where.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#73
post #63

Earlier quoted context omitted.

Awesome. I'm so glad that you have shown me the light. I now realize that we are perfectly and 100% secure right this very moment and that the security system of using the same password everywhere (e.g. password = 'password') is working out so well for people! [Also: If a user enters , how do we know for sure that they aren't entering under duress? We'd better just scrap this whole authentication thing altogether.]

I now realize that we are perfectly and 100% secure right this very moment Lol. :-) If a user enters , how do we know for sure that they aren't entering under duress? Haven't you heard of the three factors of authentication? Something they steal, something they chop off, and something they beat out of you... We'd better just scrap this whole authentication thing altogether. You can't. It's a fundamental activity, as…

  > Haven't you heard of the three factors of authentication?
  >
  > Something they steal, something they chop off, and something they
  > beat out of you...
I have, but 3-factor authentication doesn't prevent duress. If someone puts a gun to your head and tells you to enter your password + SecureID + retinal scan, what are you going to do?

  > The irony is that millions of years of evolution has given us humans
  > so much built-in natural hardware for authentication that we're now
  > doomed to underestimate the inherent complexity and subtlety of the
  > problem.
That was sort of my point. The problem is so complex that there is no silver bullet solution. The only thing that we can do is incrementally improve our solutions. Using a hash of a retinal scan as a passphrase in order to make public key cryptography more mainstream could be a good thing compared to what we have now. It wouldn't be perfect, but questions like "do you trust the hardware" are not unique to this solution. You could pose the same question about using a keyboard to enter a password.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#74
post #14

It is great that Google is open with this stuff and the security tips were mostly good, but it was inappropriate to only recommend Chrome in a security message. All modern browsers have anti-phishing features. This came off as advertising.

Chrome is generally regarded as the most secure browser around.

The sandboxed security model[1] is something nothing else offers, and it's had less exploitable security problems than any other browser.

It might be advertising, but it's also accurate.

[1] http://blog.chromium.org/2008/10/new-approach-to-browser-sec...

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#75

Earlier quoted context omitted.

do you know where he dismissed it? the article at http://www.schneier.com/essay-306.html is still up, with no disclaimer or obvious link to a correction.

why do people downvote questions like this? it makes no sense to me at all. am i doing something wrong? i thought i was polite and on-topic.

I've noticed this a lot lately.

People seem to randomly downvote a post they think is "wrong", with no explanation. Asking for one seems to make it worse.

(eg: http://news.ycombinator.com/item?id=2586625. Perhaps I was a touch rude, but a better response would have been to reply politely, point out where I was wrong and make me seem like a small-minded fool. Instead, downvotes are the response.)

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#76
post #30

Earlier quoted context omitted.

Yeah, it bothers someone: http://www.bbc.co.uk/news/world-us-canada-13614125 Just today it is widely reported the Pentagon is setting a new policy that cyber attacks can be considered acts of war which lets the Pentagon retaliate with conventional weapons. Hack my email, get an ICBM.

Posturing.

That's a good 90% of their (The DOD's) job though.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#77
post #62

Earlier quoted context omitted.

I'd expect the US to be doing the exact same thing to China. I'd be surprised if they weren't.

Pretty much this. We spy on them, they spy on us. Not much to be done about it. It used to be bugs in hotel rooms, now it's email phishing schemes.

[deleted]

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#78
post #62

Earlier quoted context omitted.

I'd expect the US to be doing the exact same thing to China. I'd be surprised if they weren't.

Pretty much this. We spy on them, they spy on us. Not much to be done about it. It used to be bugs in hotel rooms, now it's email phishing schemes.

Bingo!!

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#80
post #70

"Review the security features offered by the Chrome browser. If you don’t already use Chrome, consider switching your browser to Chrome." Nice subtle suggestion.

Indeed. I'm not sure which is more disappointing: that China seems to be bringing things to a new level or that its cool to take advantage of a situation that many people won't understand by throwing that line in there in the midst of what reads as quite scary news.

Chrome is easily the most security-focused and has the best track record of any of the major browsers. It is a totally reasonable suggestion.
Post reply on HN