Live data from Hacker News

Cosmo, the God who fell to Earth

wired.com

21–30 of 42 posts

Re: Cosmo, the God who fell to Earth

#22
post #14

The trouble is that normal operations are often indistinguishable from social engineering. I have worked several places where I have been told by management that something needs fixed on a web server, but they can't remember any passwords, so could I call up their ISP and just get it sorted. In these situations, I have never had to prove anything I couldn't have faked and I usually get asked to provide an email addre…

"Your security is based on the kindness, and apathy, of strangers."

I repeat that warning to anyone who has become just computer-savvy enough to use a computer as well as they drive their car.

The tinfoil-hat jokes have tapered off, over the years, with the mainstream news coverage of stolen user information.

Re: Cosmo, the God who fell to Earth

#23
post #21

This is really interesting. Makes me wonder why I bothered generating those hard-to-crack passwords if they can easily be reset by a bit of sweet-talking.

No joke. Cyber security's a constant game of 25 steps forward and 122 steps back.

Is that your ROT cipher?

Re: Cosmo, the God who fell to Earth

#24
post #8

In 2005, I worked support for a company with a mobile offering. At the time, app purchases were handled exclusively by the carrier and were completely opaque. A little while prior, we had partnered with a shady marketing company, netting us a bunch of unintentional signups that I had the displeasure of fixing. Since we didn't handle billing, I had to call AT&T with the customer on the line and talk them both through…

I bought a Palm Pre2 last year on ebay and had to go into an AT&T store to activate it. The person helping me had a little trouble activating it, so he called AT&T support and got help so quickly without being asked stupid questions, I've been using his technique ever since.

Whenever I call tech support of a company that has physical locations, I always start with:

"Hello, my name is Kevin, I'm an associate with [company] at the [store] location. I'm trying to help a customer with [my problem] issue..."

And very quickly I'm having a conversation with someone who knows their stuff and doesn't insult my intelligence.

Re: Cosmo, the God who fell to Earth

#25
post #11

Reading this reminds me of a gripe I have; is it possible to use 2-factor authentication on gmail without a phone? You can print a list of OTPs but you can't enable it without also registering a phone number. Given how easy it is to intercept voice and SMS, that seems like a huge security hole.

The device doesn't need to be internet connected if you use the app. An iPod Touch does the job just as well as SMS, though you need to make sure the times are synchronized.

Re: Cosmo, the God who fell to Earth

#26
post #4

What's really bad about stories like this is that social engineering is not new. I recall working on closing some of these types of loops at companies 10 years ago.

When I was reading this, I was thinking the same thing. Are the IT leads who put these systems in place forgetting the 90s?

You're assuming that anyone in these large organizations has enough control and pays enough attention to dictate how entire systems work. Usually it's more of a patchwork that gets developed over time by many people, none of whom sees the whole picture.

Re: Cosmo, the God who fell to Earth

#27

What's really bad about stories like this is that social engineering is not new. I recall working on closing some of these types of loops at companies 10 years ago.

Yea. Kevin Mitnick wrote "The Art of Deception", which is specifically about social engineering, 10 years ago from next month. And he'd been using such techniques for decades.

Re: Cosmo, the God who fell to Earth

#28
post #8

In 2005, I worked support for a company with a mobile offering. At the time, app purchases were handled exclusively by the carrier and were completely opaque. A little while prior, we had partnered with a shady marketing company, netting us a bunch of unintentional signups that I had the displeasure of fixing. Since we didn't handle billing, I had to call AT&T with the customer on the line and talk them both through…

I bought a Palm Pre2 last year on ebay and had to go into an AT&T store to activate it. The person helping me had a little trouble activating it, so he called AT&T support and got help so quickly without being asked stupid questions, I've been using his technique ever since. Whenever I call tech support of a company that has physical locations, I always start with: "Hello, my name is Kevin, I'm an associate with [com…

What do you do when they ask you access the intranet at the terminal that is obviously right infront of you?

Re: Cosmo, the God who fell to Earth

#29
post #25
post #11

Reading this reminds me of a gripe I have; is it possible to use 2-factor authentication on gmail without a phone? You can print a list of OTPs but you can't enable it without also registering a phone number. Given how easy it is to intercept voice and SMS, that seems like a huge security hole.

The device doesn't need to be internet connected if you use the app. An iPod Touch does the job just as well as SMS, though you need to make sure the times are synchronized.

Still doesn't answer my question. It won't let me turn on 2FA without giving them a phone # that can be used (SMS or voice) to authenticate, which means anyone that can redirect my phone or capture my SMS messages (both fairly trivial in a targeted attack) can bypass 2FA.

Re: Cosmo, the God who fell to Earth

#30
post #20

Oh, Wired... you write an article about a hacker and change his name to "protect" him, but publish a photograph of his neighborhood with readable house numbers and license plates.

He was doxed a long time ago, so it's not like someone who really wants to know can't find him; they still aren't going to print the name of a minor for everyone to see.
Post reply on HN