Live data from Hacker News

Techcrunch hacked by OurMine

news.ycombinator.com

11–20 of 24 posts

Re: Techcrunch hacked by OurMine

#11

I'm guessing they just pwned one of their employees via some kind of social engineering. Nothing to see here.

you say nothing to see here, but compromising high traffic sites with great potential for malware delivery to a large number of users shouldn't be a de-rigeur thing...

The fact that this has become the norm. should be a cause for concern.

Re: Techcrunch hacked by OurMine

#12
post #8

I have been following the recent hacks by the OurMine group, and find it all fascinating. If anyone knows more about the group, their motives and how they actually manage to compromise various high profile social media accounts and websites, please do share it here.

Here's a Wired article from June about them:

https://www.wired.com/2016/06/meet-ourmine-security-group-ha...

The way the article is written, the writers can't seem to be able to get handle on why they hack the places they do and if they're black hats or white hats.

Re: Techcrunch hacked by OurMine

#13

I'm guessing they just pwned one of their employees via some kind of social engineering. Nothing to see here.

WordPress VIP that hosts TechCrunch does require 2FA. Not saying it could not have been social engineering, but the usual dumb methods may not work.

Re: Techcrunch hacked by OurMine

#14
post #8

I have been following the recent hacks by the OurMine group, and find it all fascinating. If anyone knows more about the group, their motives and how they actually manage to compromise various high profile social media accounts and websites, please do share it here.

>I have been following the recent hacks by the OurMine group, and find it all fascinating.

Just some kids using someone elses tools to search through someone elses database collection. In this case the compromised journos password appears to have been "camus8" or "albertcamus8".

Don't reuse your passwords guys.

Re: Techcrunch hacked by OurMine

#15

I'm guessing they just pwned one of their employees via some kind of social engineering. Nothing to see here.

WordPress VIP that hosts TechCrunch does require 2FA. Not saying it could not have been social engineering, but the usual dumb methods may not work.

The most popular method at the moment seems to be SEing phone companies into transferring the account to a phone owned by the attacker, therefore bypassing 2FA.

Re: Techcrunch hacked by OurMine

#16
post #8

I have been following the recent hacks by the OurMine group, and find it all fascinating. If anyone knows more about the group, their motives and how they actually manage to compromise various high profile social media accounts and websites, please do share it here.

According to their website [1], they seem to be trying to establish a reputation for pentesting social-media and websites. What better way to garner interest than by hacking a couple major companies? [1]: http://ourmine.org/

What I don't understand is how they think these "marketing" tactics will establish anything but a negative reputation for their brand. Seems to me like they are happily waving a massive red flag that says, "we break the law all the time and can't be trusted!"

Re: Techcrunch hacked by OurMine

#17

Earlier quoted context omitted.

According to their website [1], they seem to be trying to establish a reputation for pentesting social-media and websites. What better way to garner interest than by hacking a couple major companies? [1]: http://ourmine.org/

What I don't understand is how they think these "marketing" tactics will establish anything but a negative reputation for their brand. Seems to me like they are happily waving a massive red flag that says, "we break the law all the time and can't be trusted!"

Why can't they be trusted? Because they break the law?

Re: Techcrunch hacked by OurMine

#18
post #8

I have been following the recent hacks by the OurMine group, and find it all fascinating. If anyone knows more about the group, their motives and how they actually manage to compromise various high profile social media accounts and websites, please do share it here.

Seems to be done with a mix of compromised (reused) credentials and social engineering. Social media accounts in particular are quite vulnerable to social engineering since they are often tied to mobile devices and it's fairly easy to contact a network operator and set up a forwarding number or request a new SIM card etc which completely bypasses most 2FA solutions.

Re: Techcrunch hacked by OurMine

#19
post #17

Earlier quoted context omitted.

What I don't understand is how they think these "marketing" tactics will establish anything but a negative reputation for their brand. Seems to me like they are happily waving a massive red flag that says, "we break the law all the time and can't be trusted!"

Why can't they be trusted? Because they break the law?

Some people believe if a person breaks one law, they may be more inclined to break other laws.

Re: Techcrunch hacked by OurMine

#20
post #14
post #8

I have been following the recent hacks by the OurMine group, and find it all fascinating. If anyone knows more about the group, their motives and how they actually manage to compromise various high profile social media accounts and websites, please do share it here.

>I have been following the recent hacks by the OurMine group, and find it all fascinating. Just some kids using someone elses tools to search through someone elses database collection. In this case the compromised journos password appears to have been "camus8" or "albertcamus8". Don't reuse your passwords guys.

Whatever service let someone get away with a 6-character password in 2016 should be put down.
Post reply on HN