Live data from Hacker News

I was seven words away from being spear-phished

robertheaton.com

121–130 of 187 posts

Re: I was seven words away from being spear-phished

#121
post #48

Earlier quoted context omitted.

I once read a theory that poor grammar, particularly with 419 scams, acts as a sort of gullibility filter where only the most susceptible targets will respond.

In this case though, since the zero day runs without consuming the attacker's time, what is to be gained by filtering out less-gullible people? If it's automated, why not cast as wide a net as possible?

Danger of discovery, perhaps? Every person who doesn’t end up judging the prize gets suspicious.

Re: I was seven words away from being spear-phished

#124

I thought 0-day exploits could be sold for a significant amount if money. I wonder if the hackers bought one, or, found one and thought they could make more on their own than by selling it? And, if they did buy one, what was the return on their investment?

If the 0-day can be sold, then what do the purchasers do to recoup their investment? Aren't attacks like this one of the main reasons that a 0-day will have value? Even malicious state-level actors will likely use the purchased vuln in an attempt to gain access to a target system (potentially via similar spear-phishing methods); although in that case their motivation will be access to information rather than financial gain.

Re: I was seven words away from being spear-phished

#125

The two questions that immediately jumped to my mind on this are 1) does Coinbase's user base skew more towards Firefox than the average, possibly because of perceived better security/privacy and a desire for that among cryptocurrency users? 2) did the zeroday impact Tor browser users, and does Coinbase have a lot of those?

The original spearphishing targeted Coinbase employees, not their users. It seems once that failed, the people behind this cast a wider net.

Re: I was seven words away from being spear-phished

#126
post #98

Earlier quoted context omitted.

Probably not a good idea to click a link you know is malicious, you never know what 0-Day they might have

That's what I keep my old Blackberry Z10 for. If I get something weird or want to go to dangerous places on internet (for research obviously) I use that thing. I'm pretty sure know one writes a 0-day for a 0.0% market share device.

This is great, finally a use for old tech!

Re: I was seven words away from being spear-phished

#127

Earlier quoted context omitted.

You may be overestimating the writing ability of native English speakers.

The kind of mistakes a non-native English speaker makes tend to be different than ones an uneducated native speaker does.

I think that lack of an article 'the' is typical of native speakers of Slavic languages?

Re: I was seven words away from being spear-phished

#128

This "spear" was also for a MacOS vulnerability. No doubt most Mac people think they're immune to viruses and malware, making this even more effective. It is very well thought out attack.

A lot of recent high profile targeted hacks have been against macos (poker stars, Saudi activist, Chinese activists, ...). Let's just agree that all platforms are vulnerable and anyone telling you otherwise should not be trusted.

All platforms are vulnerable; it does not follow that running commercial anti-malware products is good idea, or even likely to make you less vulnerable, on every platform, which is the usual context for "Macs and viruses" arguments.

Re: I was seven words away from being spear-phished

#129

This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn'…

Can any of you recommend a way to create a sandbox that can seal off processes within a computer?

One option is to use a VPC on a cloud-hosted machine to access whatever emails, links, websites someone sends you, but this can be time-consuming and costs money.

This article claims that Docker would also not be a good solution:

https://security.stackexchange.com/questions/107850/docker-a...

"...container solutions do not and never will do guarantee to provide complete isolation, use virtualization instead if you require this."

So is there any other way to create a sealed off sandbox on your own machine that would create a type of moat between your machine and your adversary?

Re: I was seven words away from being spear-phished

#130
> The joke was at least partially on them, since I’ve never owned any cryptocurrency other than a handful of Stellars that I got for free and have lost the password for. If they or any other attackers can help me get them back then I would be very grateful.

This also happened to me - and after returning to the Stellar site years later, my old login did not work, and the page looked nothing like it used to. Were the free Stellar tokens ever really granted?

Post reply on HN