Live data from Hacker News

The fake browser update scam gets a makeover

krebsonsecurity.com

101–110 of 196 posts

Re: The fake browser update scam gets a makeover

#101

Good ol' Krebs and Schneier ..either way too late to a scam, or ignoring other scams, or ineffectual regardless. What about those fake "download here" Adword buttons that have been a scourge of the web for the past decade or longer infecting untold millions of computers with malware. When will anyone bring that up.

Not sure if it's exactly the same thing as what you just mentioned, but I did write recently about criminals using paid Google ads to get their links for popular software downloads show up before even the first organic search result. And it includes the right icons and branding, and people click and are brought to a site that looks an awful lot like a site Microsoft might use to let you download Teams, and you get an…

Too bad Google seems to always be behind the curve on stopping this . Fake wallets and other scams on AdWords and Google Play store

Re: The fake browser update scam gets a makeover

#103
post #91

Earlier quoted context omitted.

I use Monero to donate to FLOSS software projects and as a way of paying friends without surveillance capitalism demanding I tell them what my private transactions are for. If these aren't "legitimate purposes" then there no point in engaging in this conversation. Maybe you're happy with being subject to corporate panopticons of Venmo/Cash App/whatever but I'd rather not engage with companies that seek to demand an e…

> Maybe you're happy with being subject to corporate panopticons of Venmo/Cash App/whatever Get this, I've never used either of these services before. And the even crazier part is that if I did, they wouldn't know what I'm giving my friends money for anyways. And lastly, just use cash if your decision making is being opressed by the surveillance capitalism. Monero serves no purpose that hasn't already been fullfilled…

Silly me, I didn't realize that I can send cash over the Internet.

Stripe's threat modeling is nothing like SecureDrop's. Stripe has plenty of identifying information that they would be forced to surrender upon subpoena that SecureDrop simply wouldn't be able to furnish because it never has that information to begin with. How is this not apparent? Comparing the two reeks of bad faith.

Re: The fake browser update scam gets a makeover

#104
Any site that asks me to change my configuration in any way to view their content gets a swift click of the Back button.

No, I will not "update" my browser nor enable JavaScript just to read your text and images.

Everyone seems to have discovered that "security" is a great excuse to coerce people into doing things.

"The only thing we have to fear, is fear itself."

Re: The fake browser update scam gets a makeover

#105
post #2

The quality of full screen takeover pages seems to have dramatically risen recently. My family members, who don’t know the Escape key exists, accidentally click one from a banner ad every week now taking them to a page like examplefoobar38561.cloudfront.net and the use of elements that imitate browser or OS chrome (generally imitating Windows Defender or similar) has reached near perfection. All browsers should have…

Full screen still requires a direct user action. So there should still be a step/click between the banner ad and the takeover. But wow.

Can't it be clicking the ad?

Re: The fake browser update scam gets a makeover

#106
post #93
post #2

The quality of full screen takeover pages seems to have dramatically risen recently. My family members, who don’t know the Escape key exists, accidentally click one from a banner ad every week now taking them to a page like examplefoobar38561.cloudfront.net and the use of elements that imitate browser or OS chrome (generally imitating Windows Defender or similar) has reached near perfection. All browsers should have…

After seeing Krebs' post the other day, we now have a call scheduled with my partner's parents who still own a Windows laptop. I'm going to tell them that they should no longer use it for any sort of financial work. No banks, no shares, nothing. Ever, for any reason. This stuff is too good now. Most of us -- and I include the tech-literate, because we all slip eventually -- are basically helpless at this point. Solut…

ChromeOS?

Re: The fake browser update scam gets a makeover

#107
post #2

The quality of full screen takeover pages seems to have dramatically risen recently. My family members, who don’t know the Escape key exists, accidentally click one from a banner ad every week now taking them to a page like examplefoobar38561.cloudfront.net and the use of elements that imitate browser or OS chrome (generally imitating Windows Defender or similar) has reached near perfection. All browsers should have…

> All browsers should have a setting to permanently block full screen mode for all sites (not “ask”). Never going to happen, because that's breaking YouTube.

Make it a permission like with audio recording etc and maybe add a whitelist for known sites.

Re: The fake browser update scam gets a makeover

#108

Every time I read about the Binance Chain, it involves a scam. Is there anything created on it that isn't that sees "wide" use in the crypto space?

I don't mean this as a particular defence of Binance chain per se - and I realise I'm not directly answering your question either - but pedestrian everyday usage of no special note would, by its very nature, go entirely unremarked, certainly by any 'news' source. It's only ever the dramatic heists, the hackings, thefts, etc, that drive reported media.

Therefore, the fact that "every time [you] read about" it, it involves some dramatic exceptional circumstance, is somewhat par-for-the-course.

By the same standard, the only things that I - as a non-enthusiast - ever read about the art world, is the extreme valuations, the thefts, the rude vandalisms. The only things I ever read about banks are the record profits, the manipulations of finance, the robberies. The only thing I ever read about the Middle East, is war.

The fact that it's mostly filled with decent ordinary people just trying to live their lives, is the boring, the unremarked yet dominant landscape, which somehow gets lost in the loud buzz of persistent drama.

Re: The fake browser update scam gets a makeover

#109

> The company said all addresses associated with the spread of the malware have been blacklisted How does this work? Can a single entity really just blacklist certain addresses? How is this decentralized?

It’s just another block chain scam: a hyped up version of a database of text files.
Post reply on HN