How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
wired.com
How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
1–10 of 107 posts
"Harris wasn’t interested in the job at Google, but he decided to crack the key and send an e-mail to Google founders Brin and Page, as each other, just to show them that he was onto their game."
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#2I hope this guy's inbox is full of job offers. That's a heck of a find.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#3Dangerous move, other companies have would set the police on him for that stunt.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#4>But the government of Iran probably could, or a large group with sufficient computing resources could pull it off.
Yes, I can see it now: Iran endures crushing sanctions in order to pursue spam email program.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#5I hope this guy's inbox is full of job offers. That's a heck of a find.
http://www.linkedin.com/in/drzacharyharris
Wow, the guy's a monster. Fluent in classical (and Levantine) Arabic, Chinese, Greek; Top Putnam score (twice), teacher, Christian missionary. Sounds like he's got drive.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#6Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#7> Harris thought there was no way Google would be so careless, so he concluded it must be a sly recruiting test to see if job applicants would spot the vulnerability. Perhaps the recruiter was in on the game; or perhaps it was set up by Google’s tech team behind the scenes, with recruiters as unwitting accomplices.
Ha! That's optimistic.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#8DKIM is an anti-spam mechanism. It does not authenticate the sender of an email message; to do that, use something like PGP. This is an interesting story, but it's not a story about a "massive net security hole". Mail on the Internet has always been spoofable.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#9“A 384-bit key I can factor on my laptop in 24 hours,” he says. “The 512-bit keys I can factor in about 72 hours using Amazon Web Services for $75. And I did do a number of those. Then there are the 768-bit keys. Those are not factorable by a normal person like me with my resources alone. But the government of Iran probably could, or a large group with sufficient computing resources could pull it off.”
"But the government of Iran probably could"...At this point I stopped reading, as this article became propaganda.
Did you know this month is National Cyber Security Awareness Month, as advertized by the DHS?
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#10Seriously old news... I attacked Facebook's 512 bit DKIM key back in 2010: http://blog.jgc.org/2010/06/facebooks-dkim-rsa-key-should-be...