Live data from Hacker News

FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

pcmag.com

31–40 of 66 posts

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#31

For people that can't grok the title and the article like me: - BasedApparel.com is a website owned by a person that happens to be the FBI director now. (he owned it before he became the director if it matters) - The website BasedApparel.com was hacked and the hackers added a malicious click here to verify you are human section that tried to have you download a malicious payload if you were on macos.

Honestly, I can't think of a more deserving bunch of people than the owner and target customers of that website. Super genius people like that need entertaining challenges in their lives to perform at their peak.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#32
post #9

Earlier quoted context omitted.

Why not both?

To what point? Do we actually think Trump would use a Trump phone? Otherwise, they'd just be getting data on die hard MAGA types that have nothing to do with anything juicy

Having 600k extremely credulous people at your beck and call is a tempting target for any powerful actor.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#33
post #21

Oh, I also got one: https://wiki.archlinux.org/index.php?title=Special:CreateAcc... > To protect the wiki against automated account creation, we kindly ask you to answer the question that appears below (more info): What is the output of: LC_ALL=C pacman -V|sed -r "s#[0-9]+#$(date -u +%m)#g"|base32|head -1 Wait, they really do that...

If you can't understand that command before pasting it in your terminal, then you probably shouldn't be editing the Arch Linux wiki.

My issue with this style of verification is more that it normalises running commands right in the terminal. Commands that come from place you kind of trust. And poof at some point it will contain some nefarious code. Instead of using a package manager (the curl to bash variant) or running these commands in a container/vm.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#34
I would like to see serious cross-party dialogue on how to avoid ending up in a situation where there’s an FBI director who sells meme clothing.

I don’t think it’s unfair to blame cowardice and venality of individual Republican politicians in the face of being primaried, although it definitely needs an asterisk that we don’t know that the left’s Senators and Congressmen would do any better under the same situation.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#36

Earlier quoted context omitted.

> he owned it before he became the director if it matters All the more reason that those who "serve" in the government should be required to divest of their business interests. The traffic such a site would get due to the tribalism prevalent in US politics makes it a fat target, and potentially a national security threat.

Im a big fan of divesting in these scenarios but i dont know how that would help in this scenario specifically. His current role and his previous ownership made the site a target, but it would be a target regardless of who owns it currently.

It is the mix of high-security high-visibility national impact with organizations that are completely unequipped to operate in that arena.

> it would be a target regardless of who owns it currently.

The commonality of attacks makes it more important to eliminate distracting dependencies for critical leaders. Not less.

There is a reason top security clearances have requirements no normal organization could make on their employers. Lack of loose vectors is even more important for leaders.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#37

> The attack seems to work by spanning various instructions that if run through macOS’s Terminal utility could steal stored credentials from Chromium-based browsers along with data from cryptocurrency wallets, placing them into a zip archive then sent to a hacker-controlled domain. What is it about Chromium based browsers that this attack narrows down to? Is it something technical in the ease of stealing information…

I wonder if they aren't using the macOS keychain, while Safari does.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#38
post #21

Oh, I also got one: https://wiki.archlinux.org/index.php?title=Special:CreateAcc... > To protect the wiki against automated account creation, we kindly ask you to answer the question that appears below (more info): What is the output of: LC_ALL=C pacman -V|sed -r "s#[0-9]+#$(date -u +%m)#g"|base32|head -1 Wait, they really do that...

If you can't understand that command before pasting it in your terminal, then you probably shouldn't be editing the Arch Linux wiki.

Also you need, to some extent, to understand that it’s something to execute in a terminal, because it doesn’t tell you that bit.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#40

Would this be a news if it was not owned by FBI director? Do we really expect the FBI director to be responsible for this? He probably outsourced it to some company. This is an inflammatory headline.

it’s absolutely news worthy.

we do (and absolutely should) have higher expectations of the head of one of the most powerful organizations in the world. said organization that goes after malicious actors makes it even more newsworthy.

Post reply on HN