Live data from Hacker News

How the Syrian Electronic Army Hacked The Onion

theonion.github.io

21–30 of 68 posts

Re: How the Syrian Electronic Army Hacked The Onion

#21
An interesting story.

> The email addresses for your twitter accounts should be on a system that is isolated from your organization’s normal email. This will make your Twitter accounts virtually invulnerable to phishing (providing that you’re using unique, strong passwords for every account).

That doesn't make a lot of sense. Sure, now your twitter account is somewhat protected against phishing (I think 'invulernable' is a bit too confident, even with 'virtually' added as qualifier).

But what about any other possible account? So now you say every single other possible account related to your business should be associated with an email address isolated from normal email, to protect them from phishing. Right?

Okay, so what makes is the 'normal email' again? You've just decided to split all your email amongst as many disparate systems as possible, to protect against phishing... which I guess it sort of does, but at cost of so much confusion that you've probably opened yourself up to something else.

Unless twitter alone is so high value to protect in this way?

Or am I missing something?

Re: How the Syrian Electronic Army Hacked The Onion

#22
post #12

Google requiring you to enter your password at random times for random things (e.g. to read a Google Groups message) seems like one contributing factor, since people treat those prompts as routine noise, and are less likely to investigate such a common occurrence too deeply.

I agree with this point. I retype my user information, even while logged in, at least a few times a week.

Re: How the Syrian Electronic Army Hacked The Onion

#24
post #22
post #12

Google requiring you to enter your password at random times for random things (e.g. to read a Google Groups message) seems like one contributing factor, since people treat those prompts as routine noise, and are less likely to investigate such a common occurrence too deeply.

I agree with this point. I retype my user information, even while logged in, at least a few times a week.

That's odd because I never do. I'm using two-factor and I only have to retype login information when that expires (approximately 30 days I believe.) Also, someone did phish my Google cookies and Google immediately shutdown my account and made me type in something from a text to reactivate my account. Overall I'm pretty happy with both of those circumstances.

Re: How the Syrian Electronic Army Hacked The Onion

#27
I thought it would be something interesting given the title..nope just something you see in your email everyday .. Maybe the Onion's next move should be to invest with a Nigerian prince.

I will forward this post to my grandfather with "Don’t let this happen to you" in bold.

/onion

Re: How the Syrian Electronic Army Hacked The Onion

#29
post #27

I thought it would be something interesting given the title..nope just something you see in your email everyday .. Maybe the Onion's next move should be to invest with a Nigerian prince. I will forward this post to my grandfather with "Don’t let this happen to you" in bold. /onion

When an email looks like it came from someone you know, and says something like:

"hey, check this out: http://blah.com "

and has their name at the bottom, it becomes very easy to make a mistake.

Re: How the Syrian Electronic Army Hacked The Onion

#30
post #9

I often think about creating a browser and email plugin/extension to help with this: - Look at all link tags. - If it looks like a URL (has a scheme at the beginning, or something which resembles a hostname, or a bunch of path or query parameters), inspect the actual link. - If they have different hosts, warn the user, and perhaps give them the option of just visiting what the contents of the link tag say (rather tha…

My brain is a bit fried, but what about a rule that "if the text contained in the tag is a FQDN, it should match the FQDN in the href exactly"? What are the false positives?

Things like Google results that go through a redirector for click tracking.
Post reply on HN