Live data from Hacker News

How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

wired.com

81–90 of 107 posts

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#81
post #29

Earlier quoted context omitted.

The reality is that people will act on "Paypal" mail that comes from "Payapal.ng". Let's not pretend that DKIM has much to do with that decision. I agree, though, that the little lock in the Gmail UI is misleading.

Just register serverX-paypal.com (where x is a number) ftw. People in general are stupid. When asked what browser they use, the overwhelming majority respond by saying "Google". That says all that needs to be said about the general public.

Quite a sad view of humanity. I don't think people are stupid, I think they just don't care and shouldn't care about the browser. It's a tool used to get access to the information they need.

I am reading HN on chrome, but unless I go looking for what browser I use, I wouldn't know.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#82

Earlier quoted context omitted.

Just register serverX-paypal.com (where x is a number) ftw. People in general are stupid. When asked what browser they use, the overwhelming majority respond by saying "Google". That says all that needs to be said about the general public.

Quite a sad view of humanity. I don't think people are stupid, I think they just don't care and shouldn't care about the browser. It's a tool used to get access to the information they need. I am reading HN on chrome, but unless I go looking for what browser I use, I wouldn't know.

Decoupling the concept of "you don't intimately know what I have spent my entire life playing with" from "stupidity" seems to be really difficult for the tech crowd.

Always sad. People willing to discount countless hours of expertise and knowledge because a user doesn't know what the name of their browser is. As if that means anything.

For example, I really don't give a shit if my neurosurgeon is aware of what his browser is named. Nor would I dream of calling him stupid if he didn't. Chances are he knows leaps and bounds more about me on most topics, just not casual desktop computing.

Likewise, discounting someone entirely because they're uncomfortable with or uninterested in computers is one of the most ridiculous, ignorant, and self-absorbed things you can do.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#83
post #29

Earlier quoted context omitted.

The reality is that people will act on "Paypal" mail that comes from "Payapal.ng". Let's not pretend that DKIM has much to do with that decision. I agree, though, that the little lock in the Gmail UI is misleading.

Just register serverX-paypal.com (where x is a number) ftw. People in general are stupid. When asked what browser they use, the overwhelming majority respond by saying "Google". That says all that needs to be said about the general public.

Why does not being intimately familiar with the structure of a URL make someone stupid exactly?

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#84

Earlier quoted context omitted.

Quite a sad view of humanity. I don't think people are stupid, I think they just don't care and shouldn't care about the browser. It's a tool used to get access to the information they need. I am reading HN on chrome, but unless I go looking for what browser I use, I wouldn't know.

Decoupling the concept of "you don't intimately know what I have spent my entire life playing with" from "stupidity" seems to be really difficult for the tech crowd. Always sad. People willing to discount countless hours of expertise and knowledge because a user doesn't know what the name of their browser is. As if that means anything. For example, I really don't give a shit if my neurosurgeon is aware of what his br…

This is about maturity and empathy, and it's certainly not exclusive to the tech crowd. [Insert half-baked pseudo-psychiatric idea about the link between tech people and empathy and Asperger's and so forth]

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#85

Earlier quoted context omitted.

Quite a sad view of humanity. I don't think people are stupid, I think they just don't care and shouldn't care about the browser. It's a tool used to get access to the information they need. I am reading HN on chrome, but unless I go looking for what browser I use, I wouldn't know.

Decoupling the concept of "you don't intimately know what I have spent my entire life playing with" from "stupidity" seems to be really difficult for the tech crowd. Always sad. People willing to discount countless hours of expertise and knowledge because a user doesn't know what the name of their browser is. As if that means anything. For example, I really don't give a shit if my neurosurgeon is aware of what his br…

This is a useful consideration. It Appears to be an affliction of many (if not all "experts") of various stripes.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#86
post #9

“A 384-bit key I can factor on my laptop in 24 hours,” he says. “The 512-bit keys I can factor in about 72 hours using Amazon Web Services for $75. And I did do a number of those. Then there are the 768-bit keys. Those are not factorable by a normal person like me with my resources alone. But the government of Iran probably could, or a large group with sufficient computing resources could pull it off.” "But the gover…

[deleted]

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#87
post #68
post #14

Earlier quoted context omitted.

Gmail (possibly Hotmail) put a little lock icon next to DKIM authenticated email from some senders, such as eBay & PayPal and outright reject unauthenticated emails from such domains. They've flaunted this feature in the past So if an authenticated PayPal email pops up in your Gmail inbox saying you must do this and that to unlock your account, you may be more likely to do so due to the legitimacy of DKIM.

Does that Padlock really have anything to do with DKIM or SPF? I thought it was just some magically hard coded thing for eBay and PayPal messages. My own DKIM signed messages certainly don't get it.

DKIM/SPF is used. However I believe both gmail and hotmail use a whitelist for the showing the padlock.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#88
post #9

“A 384-bit key I can factor on my laptop in 24 hours,” he says. “The 512-bit keys I can factor in about 72 hours using Amazon Web Services for $75. And I did do a number of those. Then there are the 768-bit keys. Those are not factorable by a normal person like me with my resources alone. But the government of Iran probably could, or a large group with sufficient computing resources could pull it off.” "But the gover…

That's your choice if you don't want to read information if it contains certain sentences. No need to tell the rest of the world about it.

The same could be said about your comment. Touché.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#89
DKIM is not the only tool for catching spoofed emails; to my knowledge SPF is more widely used because it is much easier to set up. I'd be shocked if the little Larry/Sergei joke email made it to their inbox since it would fail the SPF lookup.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#90
post #85

Earlier quoted context omitted.

Decoupling the concept of "you don't intimately know what I have spent my entire life playing with" from "stupidity" seems to be really difficult for the tech crowd. Always sad. People willing to discount countless hours of expertise and knowledge because a user doesn't know what the name of their browser is. As if that means anything. For example, I really don't give a shit if my neurosurgeon is aware of what his br…

This is a useful consideration. It Appears to be an affliction of many (if not all "experts") of various stripes.

I'm immediately tempted to apply it to politics. I won't, or at least certainly not here, but it's interesting to think about.
Post reply on HN