Live data from Hacker News

Make Your Email Hacker Proof

codinghorror.com

121–130 of 161 posts

Re: Make Your Email Hacker Proof

#121

Earlier quoted context omitted.

My name is Alan Byrne, I work in IT and I'm a password re-user :( On that note, does anyone know of a secure keysafe app that will sync across my various PCs, iPad and Android phone? This is what is stopping me from going the single use password route.

I use Keepass (or KeepassX, or KeepassDroid, and there's an iOS app too) and Dropbox.

Me too. Just remember to set the load-factor quite high. I've got it set to about 8 million rounds which is about one second on my beefy work computer, two on my private laptop and ~eight on my Android phone. The last bit is a bit annoying but at this point my key database is a pretty high value target - and I can't revoke access to it remotely if I lose my phone.

Re: Make Your Email Hacker Proof

#122
post #115

Earlier quoted context omitted.

Did you use an application specific password for Adium login? When you enable 2 factor auth, you need to generate those password for every app you use.

Yep, done that. This approach works with my 3 copies of Reeder (work, home, phone) and Calender on my phone, but for some reason Adium refuses to log in. Bug report (along with network trace) is: http://trac.adium.im/ticket/15310 I’m guessing it’s because my Google account doesn’t have a Gmail account associated with it, but Google Talk still works fine from the widget on iGoogle. Edit: opened a superuser.com questio…

I think you are right about the gmail issue. I use adium on an iMac and Macbook for work and Digsby on my Windows box at home and the application specific passwords work fine for me.

Re: Make Your Email Hacker Proof

#123

While you're thinking about the security of your email in the cloud, remember this: ANY of your email older than six months can be legally obtained by any U.S. law enforcement agency without any warrant or judicial oversight of any sort, even if you enable Google's new 46-factor authentication and use passwords that take minutes to type in. http://www.wired.com/threatlevel/2011/10/ecpa-turns-twenty-f... Do you have a…

And you think that Google actually deletes email when you tell it to? More likely they just mark it as deleted and retain it, in which case every email you ever received regardless of whether you think it has been deleted may be available. If you want better privacy, install and manage your own mail server and encrypt everything.

It is well known that google do not delete old emails. They mentioned it around when gmail started/

Re: Make Your Email Hacker Proof

#124
post #4

What I really want is for the second factor to kick on only in suspicious situations, e.g.: * I'm logging in from a computer that I've never logged in from before * I'm searching my mail history for terms like "password" * I'm opening an email that appears to contain a password-reset link * I'm messing with my mail-forwarding options * I'm accessing messages in bulk But I do not want to have to do second factor just…

Increase security/authentication as the risk factor increases based on context awareness. A number of vendors (notably CA), have been working hard to get this right. Essentially it requires a classification service that can derive context out of the content, and rate the level of risk and present the user with an additional authentication prompt (e.g.: 2-factor for exactly the scenarios you describe).

Re: Make Your Email Hacker Proof

#125
It's interesting that the "hacker" send out a mugged in Madrid email. A friend in Nepal had his Yahoo account hacked last week with the same email sent out. I wonder how they targeted people or gained access since his wife was using Gmail and is (most likely?) in a western country and my friend is from Nepal. It doesn't seem like they would be using any of the same websites.

Re: Make Your Email Hacker Proof

#126
post #122

Earlier quoted context omitted.

Yep, done that. This approach works with my 3 copies of Reeder (work, home, phone) and Calender on my phone, but for some reason Adium refuses to log in. Bug report (along with network trace) is: http://trac.adium.im/ticket/15310 I’m guessing it’s because my Google account doesn’t have a Gmail account associated with it, but Google Talk still works fine from the widget on iGoogle. Edit: opened a superuser.com questio…

I think you are right about the gmail issue. I use adium on an iMac and Macbook for work and Digsby on my Windows box at home and the application specific passwords work fine for me.

Google Talk will be tested by Google employees, and how many of them don’t have a Gmail account? :) I still feel that this should work though.

Re: Make Your Email Hacker Proof

#127
post #23
post #7

This worry seems a bit overblown to me. If your email is that important to you, you should follow these steps: 1. Use a unique , long, random, secure password. 2. Don't tell it to anyone. 3. Use an email service that stores passwords hashed with a salt and a secure hash algorithm. And you will have nothing to worry about. If you are very paranoid or traveling a lot, you can add: 4. Don't log in from insecure devices.…

6. Cross your fingers and hope that you'll never use a machine afflicted with a keylogging trojan.

You should preferably not use a computer you don't have complete control over for sensitive stuff at all. Even with two-factor authentication, a computer you don't control can still store the emails you access, etc. etc.

It's email, people. You won't die if you don't check it for three hours. And if you do... well, then you should probably've brought your own laptop (although that may make system administrators sad).

Re: Make Your Email Hacker Proof

#128
post #78

Earlier quoted context omitted.

A _startlingly_ large number of people are (still) re-using passwords across multiple sites. The Gawker/Sony(/PerlMonks for me) compromises revealed a _lot_ of email addresses and passwords, some significant portion of which almost certainly allowed attackers access not only to the specific website that was attacked, but also to the email service of the exposed user. I'm pretty sure none of Jeff's advice helps you ag…

My name is Alan Byrne, I work in IT and I'm a password re-user :( On that note, does anyone know of a secure keysafe app that will sync across my various PCs, iPad and Android phone? This is what is stopping me from going the single use password route.

I'm very satisfied with 1Password..

Re: Make Your Email Hacker Proof

#129

It's interesting that the "hacker" send out a mugged in Madrid email. A friend in Nepal had his Yahoo account hacked last week with the same email sent out. I wonder how they targeted people or gained access since his wife was using Gmail and is (most likely?) in a western country and my friend is from Nepal. It doesn't seem like they would be using any of the same websites.

Just like a lot of lead generation/spam email campaigns I've seen, I'd assume a lot of phishing and scam email "campaigns" are strictly copy and pasted from a single source (ie, a forum post somewhere), with very few scammers actually putting any effort into changing it to be somewhat unique in favor of trying to get the message to as many people as quick as possible.

Re: Make Your Email Hacker Proof

#130
post #78

Earlier quoted context omitted.

A _startlingly_ large number of people are (still) re-using passwords across multiple sites. The Gawker/Sony(/PerlMonks for me) compromises revealed a _lot_ of email addresses and passwords, some significant portion of which almost certainly allowed attackers access not only to the specific website that was attacked, but also to the email service of the exposed user. I'm pretty sure none of Jeff's advice helps you ag…

My name is Alan Byrne, I work in IT and I'm a password re-user :( On that note, does anyone know of a secure keysafe app that will sync across my various PCs, iPad and Android phone? This is what is stopping me from going the single use password route.

I've been using Firefox Sync on my desktop and Android tablet. Unfortunately, I don't think the Firefox Home app on iOS does passwords.
Post reply on HN