Live data from Hacker News

I was seven words away from being spear-phished

robertheaton.com

161–170 of 187 posts

Re: I was seven words away from being spear-phished

#161
post #149

I thought myself fairly well informed about macOS, having run it since the 10.1 days, administering it over the years, etc. But TIL that the quarantine bit and gatekeeper which normally prevent unauthorized executables from running is trivially bypassed, as was the case in this attack. My paranoia level has increased. https://objective-see.com/blog/blog_0x43.html https://speakerd.s3.amazonaws.com/presentations/9e724e…

> gatekeeper ... is trivially bypassed

It's almost as if they waste a legit user's time, and developer's nominal fees on certs, notary, etc., for something that malware will not actually be subject to.

Maybe that's a little disingenuous as Apple can work to close gaps, holes and bugs.... But when it doesn't actually stop malware in the real world and honest people need to jump through hoops, the cynic's reading is easy to make.

Similar discussion to be had around DRM.

Re: I was seven words away from being spear-phished

#162

Earlier quoted context omitted.

The kind of mistakes a non-native English speaker makes tend to be different than ones an uneducated native speaker does.

I think that lack of an article 'the' is typical of native speakers of Slavic languages?

Slavs aren't the only ones though! Romance languages, while not completely lacking articles like Slavic ones, have slightly different requirements for articles. (They tend to use them more for abstract concepts, eg. "the reality" when we would say "reality", or "the (s)" for describing general behavior/attributes of that noun -- this difference may make speakers over-correct by using articles less in English)

Re: I was seven words away from being spear-phished

#163

> Looking back it’s obviously completely absurd that the University of Cambridge would ask me to judge an economics competition I don't think this really matters all that much. I might click the link anyway to find out what it is, or to find out why I am allegedly being considered, or even just out of general curiosity. It doesn't _stop_ the attack from working.

I think a process like with unwarranted phone calls is in order. Take the name and contact info provided but Google for the information yourself and contact the official site/email/phone number for information.

A word of warning: go to the actual site and find the contact details there.

I've seen an attacker change the contact details listed on Google search results (the ones that appear in the boxes) to their own.

I saw it used as part of a Windows help center scam, but I don't see why it wouldn't work here too.

Re: I was seven words away from being spear-phished

#165
Should you ever require the services of a hacker, I implore you to try your best to hire professionals only. HACKKINGZEUS@GMAIL.COM will increase your chances of getting a successful hack. I can boldly say that he's an elite, asides the fact that I was provided a permanent solution to my credit and debt issues, he also rendered a very efficient customer service experience as he carried me along every single step of the process and didn't leave me in the dark. He's also available on 407-900-6299. Get in touch with him and be glad you did.

Re: I was seven words away from being spear-phished

#166

This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn'…

Can any of you recommend a way to create a sandbox that can seal off processes within a computer? One option is to use a VPC on a cloud-hosted machine to access whatever emails, links, websites someone sends you, but this can be time-consuming and costs money. This article claims that Docker would also not be a good solution: https://security.stackexchange.com/questions/107850/docker-a... "...container solutions do n…

On Linux-based systems, Firejail [1] is designed specifically for that (originally for Firefox?). However, it's had quite a few CVEs of its own, and I don't know how effective it is in practice protecting against 0-day-type problems.

Re: I was seven words away from being spear-phished

#167
post #6

It's always nice to get a good healthy dose of paranoia in the morning. This makes me think back to how my sec professor had a separate system that he'd use to access his online banking.

These days I'm doing something similar. Using only my iOS devices, and my Chromebook, for sensitive sites. On the Chromebook, I take it a step further by using the Android version of Firefox Focus. In theory, that gives me both the inherent security of Chrome OS, and security of the OS's Android container. Almost a poor man's version of Qubes OS in a way.

I'm not sure this is the best approach, and I'm becoming less comfortable with Google and Chrome OS on general principles, but I do feel more secure with iOS and Chrome OS than I do with general purpose computing devices.

Re: I was seven words away from being spear-phished

#168
post #48

Earlier quoted context omitted.

I once read a theory that poor grammar, particularly with 419 scams, acts as a sort of gullibility filter where only the most susceptible targets will respond.

In this case though, since the zero day runs without consuming the attacker's time, what is to be gained by filtering out less-gullible people? If it's automated, why not cast as wide a net as possible?

[deleted]

Re: I was seven words away from being spear-phished

#169

Earlier quoted context omitted.

I think that lack of an article 'the' is typical of native speakers of Slavic languages?

Slavs aren't the only ones though! Romance languages, while not completely lacking articles like Slavic ones, have slightly different requirements for articles. (They tend to use them more for abstract concepts, eg. "the reality" when we would say "reality", or "the (s)" for describing general behavior/attributes of that noun -- this difference may make speakers over-correct by using articles less in English)

Certain nouns are "inherently definite" -- names of people or places, for example, or abstractions or things which are inherently unique. Languages which mark definiteness often differ as to whether these inherently definite nouns, or which ones of them, should be marked as such. English generally treats them like proper names -- no article, definite or indefinite. Romance languages more often require the definite article. These are just two different ways of indicating the same underlying category.

Re: I was seven words away from being spear-phished

#170
post #56

Earlier quoted context omitted.

I use a dedicated VM. It is only started when I need to do some banking, and can't talk to most of the internet.

I don't get it, shouldn't you use the VM for accessing everything except your bank? If the host gets compromised from non-banking activity, it can just take over your VM.

My “solution” is that the VM is a different OS, amplifying the resources required to attack me beyond worth.
Post reply on HN