Live data from Hacker News

Why you don't steal from a hacker.

infosec20.blogspot.com

11–20 of 166 posts

Re: Why you don't steal from a hacker.

#11
>Luckily the thief was a smart little bugger and he was able to bypass the password by using an OSX install CD to create a new admin account.

So why did he rely on luck instead of SSHing to the laptop and unlocking the machine?

>I cranked up the frequency of reports to one in every five minutes to try to get a screen capture of him using gmail or facebook so I could snag a name or login credentials.

Hmm, start a keylogger (and a sniffer) in the background and then scp the logs a couple hours later?

Re: Why you don't steal from a hacker.

#12
I've been wondering about these services. Not having more information about the inner-workings of a monitoring/recovery service, I'm concerned about the company's ability to spy on me the same way I could spy on anyone who uses my stolen laptop. What prevents this from happening?

Re: Why you don't steal from a hacker.

#13
post #6

Is this one of those viral marketing campaigns again? Yesterday, there was a popular thread on Reddit about some guy who retrieved his stolen Macbook by using the exact same software that's being mentioned here. And not to mention the several other threads here on HN a few months ago that are suspiciously similar. Or maybe it's just really useful.

I have prey too - it's awesome.

Re: Why you don't steal from a hacker.

#14

>Luckily the thief was a smart little bugger and he was able to bypass the password by using an OSX install CD to create a new admin account. So why did he rely on luck instead of SSHing to the laptop and unlocking the machine? >I cranked up the frequency of reports to one in every five minutes to try to get a screen capture of him using gmail or facebook so I could snag a name or login credentials. Hmm, start a keyl…

Consumer routers will typically have port 22 firewalled for incoming trafic.

Re: Why you don't steal from a hacker.

#15
post #4

the word 'hacker' has been diluted to a new low first to 'somebody who can write a web app', to now 'somebody who can install software'

I've read some really great stories in which real hackers used SSH to log in to their stolen computers, install key loggers, and custom tools. This obviously isn't one of those stories though.

I think it is great that the average person can now do all those things from a web app. It is funny though that they still consider themselves to be hackers because they can use that web app. Another example of misuse of the term hack that I see all the time is when people use someone else's logged in Facebook session and then claim they "hacked their Facebook" because that person left their session logged in. Silly...

Re: Why you don't steal from a hacker.

#16
post #6

Is this one of those viral marketing campaigns again? Yesterday, there was a popular thread on Reddit about some guy who retrieved his stolen Macbook by using the exact same software that's being mentioned here. And not to mention the several other threads here on HN a few months ago that are suspiciously similar. Or maybe it's just really useful.

It's free and open-source. I doubt they have the budget for a viral marketing campaign.

Re: Why you don't steal from a hacker.

#17

I've been wondering about these services. Not having more information about the inner-workings of a monitoring/recovery service, I'm concerned about the company's ability to spy on me the same way I could spy on anyone who uses my stolen laptop. What prevents this from happening?

Prey is open source so, if you knew how to, you could add some monitoring capabilities to Prey to make sure it isn't doing anything it shouldn't.

Re: Why you don't steal from a hacker.

#19

I've been wondering about these services. Not having more information about the inner-workings of a monitoring/recovery service, I'm concerned about the company's ability to spy on me the same way I could spy on anyone who uses my stolen laptop. What prevents this from happening?

I suppose if you are worried about it you can use Wireshark or some other similar network traffic inspection tool to watch your traffic for suspicious communications you didn't authorize.
Post reply on HN