Live data from Hacker News

How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

wired.com

11–20 of 107 posts

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#11

Seriously old news... I attacked Facebook's 512 bit DKIM key back in 2010: http://blog.jgc.org/2010/06/facebooks-dkim-rsa-key-should-be...

I was just writing that!

It was on HN too, of course: http://news.ycombinator.com/item?id=1442385

I was surprised then that anyone would be using a 512-bit RSA key in the wild, let alone now.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#12
post #9

“A 384-bit key I can factor on my laptop in 24 hours,” he says. “The 512-bit keys I can factor in about 72 hours using Amazon Web Services for $75. And I did do a number of those. Then there are the 768-bit keys. Those are not factorable by a normal person like me with my resources alone. But the government of Iran probably could, or a large group with sufficient computing resources could pull it off.” "But the gover…

> At this point I stopped reading, as this article became propaganda.

Even if that was true (it's not), how could you know it without reading further?

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#13
post #7

> Harris thought there was no way Google would be so careless, so he concluded it must be a sly recruiting test to see if job applicants would spot the vulnerability. Perhaps the recruiter was in on the game; or perhaps it was set up by Google’s tech team behind the scenes, with recruiters as unwitting accomplices. Ha! That's optimistic.

Or paranoid. Or naive. Or narcissistic.

It might be somewhat feasible if they wanted him to be security engineer, not a devop. Still, he expected they have set up what essentially is an elaborate prank just to send a cold-call email to just one of probably numerous potential candidates.

How likely this is? What would be the risk-to-reward ratio for doing that, considering that many of unsolicited recruiting mails are not even read? Isn't it more feasible for it to be a genuine mistake on their part? Google's not infallible, omnipotent being after all.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#14
post #8

DKIM is an anti-spam mechanism. It does not authenticate the sender of an email message; to do that, use something like PGP. This is an interesting story, but it's not a story about a "massive net security hole". Mail on the Internet has always been spoofable.

Gmail (possibly Hotmail) put a little lock icon next to DKIM authenticated email from some senders, such as eBay & PayPal and outright reject unauthenticated emails from such domains. They've flaunted this feature in the past

So if an authenticated PayPal email pops up in your Gmail inbox saying you must do this and that to unlock your account, you may be more likely to do so due to the legitimacy of DKIM.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#15
post #12
post #9

“A 384-bit key I can factor on my laptop in 24 hours,” he says. “The 512-bit keys I can factor in about 72 hours using Amazon Web Services for $75. And I did do a number of those. Then there are the 768-bit keys. Those are not factorable by a normal person like me with my resources alone. But the government of Iran probably could, or a large group with sufficient computing resources could pull it off.” "But the gover…

> At this point I stopped reading, as this article became propaganda. Even if that was true (it's not), how could you know it without reading further?

What's not true? (what's 'it' that you talk about)

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#17
post #15
post #12

Earlier quoted context omitted.

> At this point I stopped reading, as this article became propaganda. Even if that was true (it's not), how could you know it without reading further?

What's not true? (what's 'it' that you talk about)

The article did not become propaganda.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#18
post #13
post #7

> Harris thought there was no way Google would be so careless, so he concluded it must be a sly recruiting test to see if job applicants would spot the vulnerability. Perhaps the recruiter was in on the game; or perhaps it was set up by Google’s tech team behind the scenes, with recruiters as unwitting accomplices. Ha! That's optimistic.

Or paranoid. Or naive. Or narcissistic. It might be somewhat feasible if they wanted him to be security engineer, not a devop. Still, he expected they have set up what essentially is an elaborate prank just to send a cold-call email to just one of probably numerous potential candidates. How likely this is? What would be the risk-to-reward ratio for doing that, considering that many of unsolicited recruiting mails are…

They could send a large number of recruitment e-mails crafted like that at negligible cost, not specifically for that one guy, and see who catches it. A little far-fetched but within the realm of possibility with a company known for geeky stuff.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#19
post #13
post #7

> Harris thought there was no way Google would be so careless, so he concluded it must be a sly recruiting test to see if job applicants would spot the vulnerability. Perhaps the recruiter was in on the game; or perhaps it was set up by Google’s tech team behind the scenes, with recruiters as unwitting accomplices. Ha! That's optimistic.

Or paranoid. Or naive. Or narcissistic. It might be somewhat feasible if they wanted him to be security engineer, not a devop. Still, he expected they have set up what essentially is an elaborate prank just to send a cold-call email to just one of probably numerous potential candidates. How likely this is? What would be the risk-to-reward ratio for doing that, considering that many of unsolicited recruiting mails are…

Back when I believed the hype, I made the same mistake with materials from Google's recruiters. They gave me driving instructions from SJC which left me in the wrong part of the valley on a Friday night during rush hour (this was before smartphone navigation). I figured it was some kind of test. It wasn't.

I called it my "cleverness attribution error" and wrote about it this summer: http://rachelbythebay.com/w/2012/06/19/attrib/

I've run into it in a few other places, too.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#20
post #13
post #7

> Harris thought there was no way Google would be so careless, so he concluded it must be a sly recruiting test to see if job applicants would spot the vulnerability. Perhaps the recruiter was in on the game; or perhaps it was set up by Google’s tech team behind the scenes, with recruiters as unwitting accomplices. Ha! That's optimistic.

Or paranoid. Or naive. Or narcissistic. It might be somewhat feasible if they wanted him to be security engineer, not a devop. Still, he expected they have set up what essentially is an elaborate prank just to send a cold-call email to just one of probably numerous potential candidates. How likely this is? What would be the risk-to-reward ratio for doing that, considering that many of unsolicited recruiting mails are…

Google has done this kind of stunt in the past. Remember {first 10-digit prime found in consecutive digits of e}.com?
Post reply on HN