Live data from Hacker News

I was seven words away from being spear-phished

robertheaton.com

111–120 of 187 posts

Re: I was seven words away from being spear-phished

#111

The specifics of this - the request to judge a prize one is clearly unqualified for - are we as software engineers particularly vulnerable to? Most people would, I think, conclude "this is fake, because why would I be asked to do this?". But I often think that as software engineers we fancy ourselves to have more insight into other fields than we really do. Does this ring true to anyone else?

> But I often think that as software engineers we fancy ourselves to have more insight into other fields than we really do.

That hypothesis is easily confirmed simply by reading HN regularly!

Re: I was seven words away from being spear-phished

#112
post #55

Earlier quoted context omitted.

Cane here to say the same thing, e.g. https://en.m.wikipedia.org/wiki/Inverkeithing_High_School Although, there's a subtle difference vs US usage: in Scotland High School is only used in the context of the name of a specific school, not as a term for the generic concept. E.g. "What secondary school did you attend?"; "I went to The High School" (meaning the Royal High School in Edinburgh). You'd never say "What high s…

Even that point varies regionally. Where I grew up, in Glasgow, it's really common to talk about primary school kids going off to high school or talk about which high school you attended.

Interesting, was this when the High school (Glasgow High) was closed? I’m not clear on the dates, but the secondary must of reopened in the early 70s.

Re: I was seven words away from being spear-phished

#116
post #18

Earlier quoted context omitted.

Elaborate?

"toaster" is pretty common argot for "low-power computer"

I immediately thought of this: https://www.embeddedarm.com/blog/netbsd-toaster-powered-by-t...

It's an actual toaster running NetBSD.

Re: I was seven words away from being spear-phished

#117
post #26

It's impossible to overestimate the power of expectations to create trust (even in the face of contrary indications). This just almost happened to me this week: A couple of days ago I wrote an email to a friend I hadn't been in touch with for several years. A day later I got a message from him on Facebook with what looked like a YouTube link and the cryptic message, "It's you?" I didn't want to see myself on a random…

Okay but let's be clear. Clicking a link won't steal your information. Going to a bad link and giving your details is how you are phished.

This attitude is exactly what the spear-fisher is hoping for! Mac people, especially, think their OS is "secure by design" (as Apple says it is) and there's no way they can be attacked.

Take another look at the article! This took advantage of a Firefox 0day that really could run software outside the brower's sandbox just by clicking on a link.

Re: I was seven words away from being spear-phished

#118
Funny that the browser that has been selling so much on privacy falls victim to such a vulnerability.

In any case, if a site says "this site must be viewed in Firefox" that would be a huge red flag, and all the more reason for me to leave. There aren't really any features in Firefox that other browsers don't have.

Re: I was seven words away from being spear-phished

#119

This "spear" was also for a MacOS vulnerability. No doubt most Mac people think they're immune to viruses and malware, making this even more effective. It is very well thought out attack.

A lot of recent high profile targeted hacks have been against macos (poker stars, Saudi activist, Chinese activists, ...).

Let's just agree that all platforms are vulnerable and anyone telling you otherwise should not be trusted.

Re: I was seven words away from being spear-phished

#120

Earlier quoted context omitted.

I doubt it in this case. It sounds like they had a browser zero-day, and could potentially steal cryptocurrencies from people they were targeting. You don't particularly care how gullible someone is; if you get your zero-day to successfully work on them and steal all their Bitcoin, there's nothing they can do about it. I think the default assumption is the correct one here; the attacker(s) are a solo or small group o…

You may be overestimating the writing ability of native English speakers.

The kind of mistakes a non-native English speaker makes tend to be different than ones an uneducated native speaker does.
Post reply on HN