Live data from Hacker News

On Getting Hacked

ahmeto.com

21–30 of 77 posts

Re: On Getting Hacked

#21
post #2

It is an humbling experience the moment when you accept that getting hacked is something that can happen to anyone, including the best of us. No one is too good not to be hacked.

I work in payments and yet I once gave my card (and 3DS auth!) to a phisher. Thankfully I realized what had happened pretty quickly and immediately deactivated the card. But the fact that I went through the whole process before realizing was pretty harrowing. For all I know, that might not have been the first time.

All it takes is an "off day" or being stressed etc. and our guard is down.

Re: On Getting Hacked

#22
post #5

> open their password manager which also might need you to authenticate, type in their master password, search for the name of the said website, copy the password, paste it in This is one way to guarantee you'll eventually fall for a phishing attack. Are we really running URL-unaware password managers in the year 2026?

>Are we really running URL-unaware password managers in the year 2026?

URL-aware browser plugins for autofilling passwords can also make people _more_ susceptible to phishing.

The password managers plugins sometimes not working correctly changes the Bayesian probabilities in the mind such that username/password fields that remain unfilled becomes normal and expected for legitimate websites. If that happens enough, it inadvertently trains sophisticated computer-literate users to lower their guard when encountering true phishing websites in the future. I wrote more on how this happens to really smart technical people: https://news.ycombinator.com/item?id=45179643

Password browser plugins being imperfect can simultaneously increase AND decrease security because of interactions with human psychology.

Re: On Getting Hacked

#23
Sadly the blogpost fails to mention which browser extension was the macilious one that compromised his session tokens.

While quite technical users (a la. this community and devs in general) would be able to inspect the source code of browser extensions to do an audit, most of us don't have time for this, and we just have to rely on the browser add-on number of downloads & reviews as a poor indicator.

It would be really useful to know how this particular extension was rated

Re: On Getting Hacked

#24
post #20
post #5

> open their password manager which also might need you to authenticate, type in their master password, search for the name of the said website, copy the password, paste it in This is one way to guarantee you'll eventually fall for a phishing attack. Are we really running URL-unaware password managers in the year 2026?

That's a very smug take, especially when you encounter websites every day that don't autofill for whatever reason (As another poster already showed with some examples) or in my case the 1Password extension in Safari failing to connect to the main 1Password deamon or a number of other issues that make this still common place in 2026. And that's for me, a technical user using a password manager.

I also find the 1Password browser (Safari) extension to pitifully poor. But there's a neat workaround: set up a hotkey for 'Show Quick Access'. I use Ctrl+Opt+\.

This pops up 1Password's overlay but it is still URL-aware. I find it works almost universally. It'll show you what it's going to fill: just hit Return and it'll be done.

It doesn't even care what browser you're in. Works across the lot. Of course it isn't fully integrated so Passkeys won't work.

Re: On Getting Hacked

#25
> but on a universal level, we're missing a cohesive master plan, in which a user, a human, need not undertake endless and repeated manual fend-off of the devil

This is a very good way of stating the problem in terms anyone can relate to.

> I had one brow raised, a little suspicious, but not very much to initiate a full-scale defense

This on the other hand seems overly superficial. You get your eMarketplace account hacked, then your Twitter account, and you're just "a little suspicious"? My eyebrows would raise all the way to the back of my head after this. Not sure I'd know where to start but I'd be very concerned.

> A few days later, the same thing happened with my TikTok and Reddit accounts. I repeated the previous steps now that I had gotten used to them. This time I raised two of my brows with a little more suspicion. Still not quite there, though.

I mean... This is an incredibly high threshold for getting concerned. The kind that lowers the bar to getting hacked.

Re: On Getting Hacked

#26

Sadly the blogpost fails to mention which browser extension was the macilious one that compromised his session tokens. While quite technical users (a la. this community and devs in general) would be able to inspect the source code of browser extensions to do an audit, most of us don't have time for this, and we just have to rely on the browser add-on number of downloads & reviews as a poor indicator. It would be real…

Totally. This would have been vital.

Re: On Getting Hacked

#27

Sadly the blogpost fails to mention which browser extension was the macilious one that compromised his session tokens. While quite technical users (a la. this community and devs in general) would be able to inspect the source code of browser extensions to do an audit, most of us don't have time for this, and we just have to rely on the browser add-on number of downloads & reviews as a poor indicator. It would be real…

Hi, OP here:

Unfortunately, with a brisk urge to clean it all up, I hadn't paid attention to which extension it was that got my browser compromised; I had immediately removed all extensions, cleared browser data, stopped the sync, and uninstalled it altogether (for fear of getting further compromised).

What I can say is that I have tried a number of extensions for the purpose of making a website in dark theme, for ease of reading, which weren't as popular (in terms of rating & installs), and highly likely that those were malware.

That being said, I now hesitate to even install extensions that are selected by the Google Chrome editor team. I vibe-coded a simple extension myself to use as a "dark reader", and will probably avoid installing anything anymore. I got my fair share of damage.

Re: On Getting Hacked

#28
post #19
post #10

> At this point, I am the old lady who is driving to a Target to buy gift cards and give them to Jared, who is the Amazon Customer Support specialist with a suspiciously heavy Indian accent, waiting on the phone. It happens to all of us. I always tend to make sure any extension has the sources available (unless requested by work/client), but nowadays with open source supply chain attack, it's just another breakable w…

Running Asahi? or otherwise, How did a trojan slip through disguised as an init system which does not exist on darwin. (this is all assuming by "my m3 laptop" you are referring to apple silicon.. so i could be way off base)

I see the confusion. My fault. Before the Mac M3, intel briefly used to have the intel core m3 cpu lineup. Fanless, and very energy efficient for the time (~2017).

Re: On Getting Hacked

#29
post #5

> open their password manager which also might need you to authenticate, type in their master password, search for the name of the said website, copy the password, paste it in This is one way to guarantee you'll eventually fall for a phishing attack. Are we really running URL-unaware password managers in the year 2026?

I'm using Apple's Password Manager (native app on iOS & macOS), but didn't install its browser extension that can do autofill because for me it wasn't as convenient (it has a bad UX, unreliable autofill, etc.)

So, when I'm prompted to log in somewhere, I open the password manager and repeat the steps you just mentioned. It does add extra steps to the process, but I don't think it makes it less safe than having an autofill extension, which requires a ton of permissions and is more prone to compromises. And yes, my manual method also means I have to rely on me being aware of the URLs I'm on, but I usually bookmark my main services, so it's working fine for me this way. I also treat all emails as spam and/or an attack unless I verify them by the domain, and whether I had just recently requested to log in or requested a password change, etc.

At the end of the day, it boils down to us paying attention to every action we take, regardless of the measures we take, as new and different methods are being deployed to own us every day.

Re: On Getting Hacked

#30

I got hacked late last year. It sucked. Do not recommend. I'm not going to blog about it, but will at least share how I messed up. Maybe it'll help someone else. I was phished through Discord. A CEO that I was friends with was phished prior to me and I let my guard down when someone I put on a pedestal reached out to me. The hacker asked me to review a video game prototype they'd been tinkering with in their spare ti…

For a cautionary tale, I'm not seeing a mention of how you were actually compromised? You mentioned losing multiple accounts, but presumably didn't decide to sign up for their 'game' website while entering your gmail address and password plus Discord password. KeePass should rule out having used the same password for all three accounts. KeePass should also, in theory, not immediately give up all of your credentials to a random .exe running on your computer. If it did, it would be useful for people to know to avoid it.
Post reply on HN