Live data from Hacker News

How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

wired.com

1–10 of 107 posts

How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#1
"Harris wasn’t interested in the job at Google, but he decided to crack the key and send an e-mail to Google founders Brin and Page, as each other, just to show them that he was onto their game."

How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
wired.com

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#5
post #2

I hope this guy's inbox is full of job offers. That's a heck of a find.

http://www.linkedin.com/in/drzacharyharris

Wow, the guy's a monster. Fluent in classical (and Levantine) Arabic, Chinese, Greek; Top Putnam score (twice), teacher, Christian missionary. Sounds like he's got drive.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#7
> Harris thought there was no way Google would be so careless, so he concluded it must be a sly recruiting test to see if job applicants would spot the vulnerability. Perhaps the recruiter was in on the game; or perhaps it was set up by Google’s tech team behind the scenes, with recruiters as unwitting accomplices.

Ha! That's optimistic.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#8
DKIM is an anti-spam mechanism. It does not authenticate the sender of an email message; to do that, use something like PGP. This is an interesting story, but it's not a story about a "massive net security hole". Mail on the Internet has always been spoofable.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#9
“A 384-bit key I can factor on my laptop in 24 hours,” he says. “The 512-bit keys I can factor in about 72 hours using Amazon Web Services for $75. And I did do a number of those. Then there are the 768-bit keys. Those are not factorable by a normal person like me with my resources alone. But the government of Iran probably could, or a large group with sufficient computing resources could pull it off.”

"But the government of Iran probably could"...At this point I stopped reading, as this article became propaganda.

Did you know this month is National Cyber Security Awareness Month, as advertized by the DHS?

http://www.dhs.gov/national-cyber-security-awareness-month

Post reply on HN