Live data from Hacker News

How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

wired.com

101–107 of 107 posts

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#101
post #29

Earlier quoted context omitted.

The reality is that people will act on "Paypal" mail that comes from "Payapal.ng". Let's not pretend that DKIM has much to do with that decision. I agree, though, that the little lock in the Gmail UI is misleading.

Just register serverX-paypal.com (where x is a number) ftw. People in general are stupid. When asked what browser they use, the overwhelming majority respond by saying "Google". That says all that needs to be said about the general public.

"People" includes major websites like Amazon and banks that send official email from phishy domain names.

I have mistakenly reported several Amazon security emails to their phishing team.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#102

Earlier quoted context omitted.

Just register serverX-paypal.com (where x is a number) ftw. People in general are stupid. When asked what browser they use, the overwhelming majority respond by saying "Google". That says all that needs to be said about the general public.

Why does not being intimately familiar with the structure of a URL make someone stupid exactly?

Same reason handing your wallet to a stranger who calls himself Dr. Bankersmith is stupid.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#103
post #78

Earlier quoted context omitted.

Framing it as a mere anti-spam weakness rather than anti-phishing is kinda disingenuous.

Here I'm just going to refer you to "Three Myths About DKIM", linked from the front page of the DKIM site: http://jl.ly/Email/threemyths.html

None of those myths talk about spoofing the sender domain.

DKIM doesn't validate the From line. But where is the weakness in trusting that someone with Google's private key approved the entire content of a message that is signed with Google's key, and so, my trust in Google should extend to the content of that email?

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#104
post #28

Earlier quoted context omitted.

It authenticates the domain of the sender, right?

If you want to impute that much authority to it, sure, but the actual signature verification depends on the insecure DNS anyways. Do not make security decisions based on DKIM. It's an anti-spam mechanism and that's all.

How does that signature verification work? Something like a callback to paypal.com to get the verification? (Analogous to downloading an SSL cert from a website without using a trusted side channel like a handwritten note?)

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#105

Earlier quoted context omitted.

The chess champion Capablanca said that he was protected from losing games due to minor blunders because his opponents assumed he was so brilliant that he saw something they didn't, so they played safe and avoided taking advantage.

I think I read an article recently (probably highlighted on HN) that talked about how Deep Blue did exactly this versus Kasparov. A bug caused it to make a sub-optimal move, and it's quite likely Garry misinterpreted it as genius and psyched himself out going forward.

Yeah I'd read that. Kasparov was pretty freaked out by Deep Blue. He wrote this:

"I got my first glimpse of artificial intelligence on Feb. 10, 1996, at 4:45 p.m. EST, when in the first game of my match with Deep Blue, the computer nudged a pawn forward to a square where it could easily be captured. It was a wonderful and extremely human move. If I had been playing White, I might have offered this pawn sacrifice. It fractured Black's pawn structure and opened up the board. Although there did not appear to be a forced line of play that would allow recovery of the pawn, my instincts told me that with so many "loose" Black pawns and a somewhat exposed Black king, White could probably recover the material, with a better overall position to boot. "

about a move most computers of the time would find pretty quickly, and most decent human players would intuitively have thought OK at first glance.

http://www.azillionmonkeys.com/qed/chess.html

My theory is that a significant part of his game was based around human psychology, so he found it hard to grasp computers. He played computer-friendly risky openings as if to taunt the machine, and heavily talked up the influence of the programmers on Deep Blue to an almost paranoid extent.

The result was that he lost against Deep Blue when he should have won fairly easily if he'd been more disciplined.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#106
post #103
post #78

Earlier quoted context omitted.

Here I'm just going to refer you to "Three Myths About DKIM", linked from the front page of the DKIM site: http://jl.ly/Email/threemyths.html

None of those myths talk about spoofing the sender domain. DKIM doesn't validate the From line. But where is the weakness in trusting that someone with Google's private key approved the entire content of a message that is signed with Google's key, and so, my trust in Google should extend to the content of that email?

I already provided one specific example upthread: most domains people care about host applications with bugs that allow attackers to generate arbitrary mail from those domains. This is, please note, a very different problem than "being able to generate arbitrary mail under a specific signature". It is considerably easier to forge mail from BANKOFAMERICA.COM than it is to forge mail under the S/MIME signature of a specific Bank of America employee.

Domains simply are not a meaningful security boundary. At no point in the life of the commercial Internet have they ever been. Yes, there are security mechanisms on the Internet that are simultaneously (a) important and (b) misguided enough to ignore this fact. Fortunately, the most important of them are in practice difficult to reliably and scalably exploit.

This whole story is a tempest in a teacup. As Matthew Green said on Twitter: a 512 bit DKIM key says more about how little Google cares about DKIM than it does about any laxity on Google's part. Google is not lax about security.

Since this thread is also dead, we'll have to wait until someone else tries to get to the top of the front page with a DKIM story to continue arguing about DKIM.

Re: How a Google Headhunter’s E-Mail Unraveled a Massive Net Security Hole

#107
post #102

Earlier quoted context omitted.

Why does not being intimately familiar with the structure of a URL make someone stupid exactly?

Same reason handing your wallet to a stranger who calls himself Dr. Bankersmith is stupid.

How in the hell is that even somewhat similar?
Post reply on HN