How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
71–80 of 107 posts
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#72Earlier quoted context omitted.
Or paranoid. Or naive. Or narcissistic. It might be somewhat feasible if they wanted him to be security engineer, not a devop. Still, he expected they have set up what essentially is an elaborate prank just to send a cold-call email to just one of probably numerous potential candidates. How likely this is? What would be the risk-to-reward ratio for doing that, considering that many of unsolicited recruiting mails are…
Back when I believed the hype, I made the same mistake with materials from Google's recruiters. They gave me driving instructions from SJC which left me in the wrong part of the valley on a Friday night during rush hour (this was before smartphone navigation). I figured it was some kind of test. It wasn't. I called it my "cleverness attribution error" and wrote about it this summer: http://rachelbythebay.com/w/2012/0…
I think you are being very diplomatic. :)
But seriously, this cleverness attribution error might be a big problem with large players like Google. Forum posters, blogs and the digital versions of mainstream media all seem convinced Google is somehow special. That they know what they are doing, at every turn. Assuming some silly mistakes is a "test". It's a potentially harmful meme: people assuming ideas like "genius" or "utmost comptetence" without requiring any proof.
Blind faith followers take note, because here we have _proof_ that Google makes mistakes too. Silly ones at that.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#73Here's my take: DKIM is an attempt by _third parties_ (i.e. "email providers", not the author or the recipient of the message) to control who can send email (but guess what? anyone can send email, go figure). On the other hand, authentication (PGP) is an attempt to allow senders to sign messages and receivers to verify signatures (no third parties needed).
Bob printed his PGP public key on a card and gave it to Alice when they had lunch. He then signed an email message the following week using PGP and sent it to Alice. But Bob's "email provider" decided to block Bob's message because Bob didn't pay money to someone for the use of a "domain name" and Bob's "email provider" thought his email was "spam" because he hadn't been "authorized" (by paying money for use of a domain name) to send email.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#74Earlier quoted context omitted.
Saying that DKIM doesn't adequately verify an email is genuine ignores the point of DKIM which is to weed out emails that clearly aren't genuine. So Gmail can simply deadpool hundreds of fake paypal phishing emails. That doesn't mean the occasional one that gets through by fooling DKIM is authentic - but the security benefits exist. Unfortunately, in quibbling over the headline, which you are free to do, you argued t…
What seems to be happening here is that you don't like the fact that I criticized the Wired headline, so you're moving the goalposts from "Massive Net Security Issue" to "Thing That Might Make It Harder For Google To Reject Spam". Then, when I point out that you're moving the goalposts, you respond by simply repeating the claim --- and then suggest that pointing out what DKIM actually is amounts to a "quibble". DKIM…
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#75Earlier quoted context omitted.
http://www.linkedin.com/in/drzacharyharris Wow, the guy's a monster. Fluent in classical (and Levantine) Arabic, Chinese, Greek; Top Putnam score (twice), teacher, Christian missionary. Sounds like he's got drive.
Nit-picky corrections: 1. Top Putnam score in Colorado . There's a pretty big difference between that, and say, top Putnam score in Massachusetts (which is more likely the same as top overall due to many Putnam Fellows coming from Harvard or MIT). 2. Elementary proficiency in Classical and Leventine Arabic, Mandarin Chinese, and Koine Greek
http://www.colorado.edu/news/series/cu-boulder-nobel-laureat... (add David Wineland to that list).
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#76Earlier quoted context omitted.
Saying that DKIM doesn't adequately verify an email is genuine ignores the point of DKIM which is to weed out emails that clearly aren't genuine. So Gmail can simply deadpool hundreds of fake paypal phishing emails. That doesn't mean the occasional one that gets through by fooling DKIM is authentic - but the security benefits exist. Unfortunately, in quibbling over the headline, which you are free to do, you argued t…
What seems to be happening here is that you don't like the fact that I criticized the Wired headline, so you're moving the goalposts from "Massive Net Security Issue" to "Thing That Might Make It Harder For Google To Reject Spam". Then, when I point out that you're moving the goalposts, you respond by simply repeating the claim --- and then suggest that pointing out what DKIM actually is amounts to a "quibble". DKIM…
DKIM plays a key role in keeping phishing e-mails out of the inboxes of hundreds of millions of people who have no idea what PGP or an e-mail header is. It's a standard, not just a Google feature.
And if you'd read the story, you'd see that a number of companies fixed their weak crypto thanks to his efforts.
But, of course, far fewer people would upvote your comments if you didn't diss everything with a tone of condescension.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#77Earlier quoted context omitted.
What seems to be happening here is that you don't like the fact that I criticized the Wired headline, so you're moving the goalposts from "Massive Net Security Issue" to "Thing That Might Make It Harder For Google To Reject Spam". Then, when I point out that you're moving the goalposts, you respond by simply repeating the claim --- and then suggest that pointing out what DKIM actually is amounts to a "quibble". DKIM…
I know you are the resident curmudgeonly voice of security truthfulness on Hacker News, but it's really odd that you keep referring to anti-phishing measures as anti-spam, as if they have no relation whatsoever to security. DKIM plays a key role in keeping phishing e-mails out of the inboxes of hundreds of millions of people who have no idea what PGP or an e-mail header is. It's a standard, not just a Google feature.…
DKIM is an anti-spam mechanism. It does not authenticate the sender of an email message; to do that, use something like PGP. This is an interesting story, but it's not a story about a "massive net security hole". Mail on the Internet has always been spoofable.
What else do you want me to say? Mail on the Internet is spoofable, with or without DKIM. I literally don't know what I can do to placate you at this point.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#78Earlier quoted context omitted.
What seems to be happening here is that you don't like the fact that I criticized the Wired headline, so you're moving the goalposts from "Massive Net Security Issue" to "Thing That Might Make It Harder For Google To Reject Spam". Then, when I point out that you're moving the goalposts, you respond by simply repeating the claim --- and then suggest that pointing out what DKIM actually is amounts to a "quibble". DKIM…
Framing it as a mere anti-spam weakness rather than anti-phishing is kinda disingenuous.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#79Earlier quoted context omitted.
Gmail (possibly Hotmail) put a little lock icon next to DKIM authenticated email from some senders, such as eBay & PayPal and outright reject unauthenticated emails from such domains. They've flaunted this feature in the past So if an authenticated PayPal email pops up in your Gmail inbox saying you must do this and that to unlock your account, you may be more likely to do so due to the legitimacy of DKIM.
Does that Padlock really have anything to do with DKIM or SPF? I thought it was just some magically hard coded thing for eBay and PayPal messages. My own DKIM signed messages certainly don't get it.
Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole
#80Earlier quoted context omitted.
Gmail (possibly Hotmail) put a little lock icon next to DKIM authenticated email from some senders, such as eBay & PayPal and outright reject unauthenticated emails from such domains. They've flaunted this feature in the past So if an authenticated PayPal email pops up in your Gmail inbox saying you must do this and that to unlock your account, you may be more likely to do so due to the legitimacy of DKIM.
The reality is that people will act on "Paypal" mail that comes from "Payapal.ng". Let's not pretend that DKIM has much to do with that decision. I agree, though, that the little lock in the Gmail UI is misleading.