Live data from Hacker News

How the Syrian Electronic Army Hacked The Onion

theonion.github.io

11–20 of 68 posts

Re: How the Syrian Electronic Army Hacked The Onion

#12
Google requiring you to enter your password at random times for random things (e.g. to read a Google Groups message) seems like one contributing factor, since people treat those prompts as routine noise, and are less likely to investigate such a common occurrence too deeply.

Re: How the Syrian Electronic Army Hacked The Onion

#14
post #9

I often think about creating a browser and email plugin/extension to help with this: - Look at all link tags. - If it looks like a URL (has a scheme at the beginning, or something which resembles a hostname, or a bunch of path or query parameters), inspect the actual link. - If they have different hosts, warn the user, and perhaps give them the option of just visiting what the contents of the link tag say (rather tha…

My brain is a bit fried, but what about a rule that "if the text contained in the tag is a FQDN, it should match the FQDN in the href exactly"?

What are the false positives?

Re: How the Syrian Electronic Army Hacked The Onion

#17
post #9

I often think about creating a browser and email plugin/extension to help with this: - Look at all link tags. - If it looks like a URL (has a scheme at the beginning, or something which resembles a hostname, or a bunch of path or query parameters), inspect the actual link. - If they have different hosts, warn the user, and perhaps give them the option of just visiting what the contents of the link tag say (rather tha…

One word: mutt.

Re: How the Syrian Electronic Army Hacked The Onion

#18
post #3

> "Please read the following article for its importance" This immediately hit my brain's bayesian classifier like a ton of bricks. Or as the saying goes, "If spammers ever learn proper English, god help us all." * the English is actually proper, but the wording is unusual

It doesn't work for spear phishing, but for wide-ranging hits the broken english is often on purpose: http://research.microsoft.com/pubs/167719/whyfromnigeria.pdf :: http://www.onthemedia.org/2012/aug/31/why-nigerian-email-sca...

tldr: you have a lower number of leads but a higher conversion rate from those that do respond.

Re: How the Syrian Electronic Army Hacked The Onion

#19
post #15
post #2

One more reason to use 2FA on your Google Apps account.

2FA is great, but it wouldn't save you here if you ask it to remember you for 30 days.

It would have stopped someone from using a phished GApps credential from logging in to Google using it, though.

It sounds like one prong of the attack was to gain access to one employee's email, then use that account to send phishing emails to other employees. 2FA would have stopped that.

Re: How the Syrian Electronic Army Hacked The Onion

#20
post #15
post #2

One more reason to use 2FA on your Google Apps account.

2FA is great, but it wouldn't save you here if you ask it to remember you for 30 days.

Can you explain? I use 2FA and tell it to remember me on this device, right?

If a Syrian hacker phished my password, he wouldn't be able to login on his system, would he?

Post reply on HN