Live data from Hacker News

How My Mom Got Hacked

nytimes.com

91–100 of 111 posts

Re: How My Mom Got Hacked

#91
post #82

Earlier quoted context omitted.

Jesus. The publisher is the New York Times, writing a story about a real threat to ordinary people. It's not a great headline, but neither is it really misleading either. It effectively communicates what the article is about to SNYT readers. Apparently anything that is not 100% dull now is clickbait.

It's not about being dull, or exciting, and it's not about click-bait or otherwise. It's about accuracy, reporting, and expectations. The heading was "How My Mom Got Hacked" so I expected to see something about how her mom got hacked. But I didn't. It was a great story about what happened after her mom got hacked, and it was interesting, and mildly engaging, but it simply wasn't what it said. Calling it something lik…

Yes! Reporters usually don't get to write their own headlines.

(you can swap in "publications" without really changing what you meant, but I guess it's fair to not blame reporters)

Re: How My Mom Got Hacked

#92

Earlier quoted context omitted.

Not really. Most useful technologies can be used in crime and we'd get nowhere if we allowed that fact to be used as an argument against the technology. Pre-Bitcoin, the scammer would have her call an expensive foreign premium-rate phone number or mail cash to a foreign address.

How about when in a few years time there's a scalable, functioning market for hits/murders with bitcoin as payment? I love the elegance of the bitcoin protocol, but I am worred that the civilized world will have to clamp down on it. You just can't have a place where anyone with enough money (a few k EUR/USD) can perform murders without any reasonable risk of being exposed. This will effectively turn us into a bandit…

> You just can't have a place where anyone with enough money (a few k EUR/USD) can perform murders without any reasonable risk of being exposed.

I strongly suspect that we will see a whitelist-endorsed-by-some-reputation-broker approach sometime in the future. The suggestion of this kind of thing usually creates a big backlash among many Bitcoin supporters (for good reasons IMO). But eventually there will be many folks using Bitcoin without any ideological attachment to it, and they'll be lured by the appeal of interacting with agents endorsed by some other party.

Re: How My Mom Got Hacked

#93
post #82

Earlier quoted context omitted.

Jesus. The publisher is the New York Times, writing a story about a real threat to ordinary people. It's not a great headline, but neither is it really misleading either. It effectively communicates what the article is about to SNYT readers. Apparently anything that is not 100% dull now is clickbait.

It's not about being dull, or exciting, and it's not about click-bait or otherwise. It's about accuracy, reporting, and expectations. The heading was "How My Mom Got Hacked" so I expected to see something about how her mom got hacked. But I didn't. It was a great story about what happened after her mom got hacked, and it was interesting, and mildly engaging, but it simply wasn't what it said. Calling it something lik…

Is it too much to ask that you use some imagination rather than blandly parse a headline?

Re: How My Mom Got Hacked

#94
post #93

Earlier quoted context omitted.

It's not about being dull, or exciting, and it's not about click-bait or otherwise. It's about accuracy, reporting, and expectations. The heading was "How My Mom Got Hacked" so I expected to see something about how her mom got hacked. But I didn't. It was a great story about what happened after her mom got hacked, and it was interesting, and mildly engaging, but it simply wasn't what it said. Calling it something lik…

Is it too much to ask that you use some imagination rather than blandly parse a headline?

Sorry, but I really don't understand that comment. I read the article, and commented that the title doesn't match the content. In what sense do you then claim that I've just blandly parsed a headline?

Re: How My Mom Got Hacked

#95

And that is why I have the "if you don't have backup, I won't bother to help you with your lost files" policy when friend or family come crying. I make only one exception from this rule. Cryptolocker is not the problem. The lack of reliable backup is. 15 years into the internet age, and 5 into the cloud you have no excuse.

And after the backup don't forget to detach the external storage and logout from the cloud storage otherwise they could just encrypt those too.

Re: How My Mom Got Hacked

#96
I don't see any mention here, but as someone who deals with front-line response to users regularly, take a look at CryptoPrevent from FoolishIT (yes, really, https://www.foolishit.com/vb6-projects/cryptoprevent/) and HitmanPro.Alert (http://www.surfright.nl/en/alert) with CryptoGuard. The first does a bunch of local policy setup to restrict where executables can run along with some optional subscription signature watching;the second does more watching for encrypting behavior including on a host sharing files via SMB.

I also recommend making sure that shadow copies are turned on and allocated plenty of space - including on a separate partition or drive if the user in question regularly comes close to filling the drive. It's not a backup, but it is much faster to restore from a shadow copy than from an offsite backup.

edit: added links

Re: How My Mom Got Hacked

#97
post #85
post #83

Earlier quoted context omitted.

That actually may be a very good idea. It's not that non-experts should be forbidden from using these thing it is that we should stop handing people guns that they end up using to shoot themselves in the foot with.

Agreed – I'm not cheerful about the implications of making things less user-serviceable but … it's not like we don't know how well that's worked out. If you haven't already read it, SwiftOnSecurity's “A story about Jessica” is rather good for illustrating how badly we've failed as an industry to produce devices which are safe for non-experts to use: http://swiftonsecurity.tumblr.com/post/98675308034/a-story-a...

Thats a cool article.

On the other hand, WTF is up with that blog?!?

Re: How My Mom Got Hacked

#98

I don't see any mention here, but as someone who deals with front-line response to users regularly, take a look at CryptoPrevent from FoolishIT (yes, really, https://www.foolishit.com/vb6-projects/cryptoprevent/ ) and HitmanPro.Alert ( http://www.surfright.nl/en/alert ) with CryptoGuard. The first does a bunch of local policy setup to restrict where executables can run along with some optional subscription signature…

CryptoWall apparently delete shadow copies with a simple vssadmin command.

http://stopmalvertising.com/malware-reports/cryptowall-behin...

Re: How My Mom Got Hacked

#99

So the title is "How My Mom Got Hacked" and the only thing it actually says about that actual title is: The virus is thought to infiltrate your computer when you click on a legitimate-looking attachment or through existing malware lurking on your hard drive, ... So, there's really nothing about how his mom got hacked. Don't get me wrong, it's an interesting article, interesting to read about the process that ensues o…

What do you call the opposite of clickbait? I thought the article was more interesting than I originally expected.

Re: How My Mom Got Hacked

#100

I don't see any mention here, but as someone who deals with front-line response to users regularly, take a look at CryptoPrevent from FoolishIT (yes, really, https://www.foolishit.com/vb6-projects/cryptoprevent/ ) and HitmanPro.Alert ( http://www.surfright.nl/en/alert ) with CryptoGuard. The first does a bunch of local policy setup to restrict where executables can run along with some optional subscription signature…

CryptoWall apparently delete shadow copies with a simple vssadmin command. http://stopmalvertising.com/malware-reports/cryptowall-behin...

Good to know; I've only dealt with a couple and they were on workstations that encrypted files on mapped network shares - vssadmin wouldn't have any access to remove shadow copies on the file server, and in all but one of those cases we had both shadow copies locally on the file server and offsite file backups in place (backups only for the last).
Post reply on HN