This is a silly article with an alarmist title. They look at a list of sites she likes on Facebook, then they phish her from one of them. Then she lets them into her house where they look for post-it notes with passwords on them. For a grand finale, they open her garage door. I guess the takeaway here is don't let people that identify themselves as "hackers" through your door and into your home office if you have pas…
The title isn't alarmist. The victim was an ordinary who didn't have a particularly "IoT" home and wasn't a heavy Internet user. They were hacked successfully. It is a useful article as a warning for non-technical people.
Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
31–40 of 74 posts
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#32Earlier quoted context omitted.
Don't trust password managers. They are hackable pieces of software just like the ones you are trying to protect. And they are not reliable (see last news of Lastpass acquisition by LogMeIn). I'm not saying you should ditch password managers and just memorize all of your password. I'm just saying: use them as a well-informed user. Back in the days, Bruce Schneier suggested to write passwords down on a piece of paper…
Not all password managers are commercial, closed-source, and cloud-connected. This probably wasn't a main point of yours, but since you mentioned LastPass I felt this should be clarified. I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser. I've been thinking about…
With X selection buffers, when you're pasting data the X application you're pasting from gets to run arbitrary code (informed of the destination!) to determine what to send. I've been wanting a password manager that asks me for verification before transferring the data.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#33Earlier quoted context omitted.
Haha, I also thought your comment was a response to what I edited-in about my hardware idea, but yes, we must have been writing it at the same time. When Bitcoin hardware wallets were first getting developed, I wondered why people didn't just start with open, barebones commodity hardware like you've described. Well, I suppose one reason may be that it may not exist, but it seems like it should be pretty cheap to pay…
For radio-free hardware, what about a Palm Pilot? Only has IrDA.
You're very very unlikely going to want to type a truly secure (= long) password over and over and over, which you'd need to do in a situation where the browser's password manager is turned off, and/or a website disables password caching anyway.
The Palm m5xx series could solve this problem: it had full USB, and I once read of an Palm app (like any other) that bridged the m5xx's SD slot to behave like a block device over USB, ie it turned the Palm into a USB SD card reader. That means there's a raw USB SDK out there, and adding HID keyboard support wouldn't be too hard (no kernel driver development etc).
Getting passwords into the device would be nontrivial; Palm keyboards are proprietary to the series they were made for, with a few arbitrary connector updates thrown in for good measure (think iPhone docking connector saga). If the password is irritating enough to repeatedly type on a full keyboard, it would take you a good 5 minutes (and a punching bag, for afterwards) to get it into the PDA, Graffiti and custom keyboards taken into account.
I think it would work out though: if the only way to get data out of the device is to tap something on its screen, that should be enough of a brick wall to dissuade would-be attackers.
I guess I'm responding to this so enthusiastically because it's about Palm :P - I unfortunately never owned one of these awesome little things, but I'd love something of similar capabilities built using today's tech. With modern advances in power consumption, like MemoryLCD, micropower CPUs, short-range bluetooth, etc, the result would probably last literally weeks. It'd be enormous fun to hack on, too, and carve out a little niche for itself. :)
I wonder if I should Ask HN if this would be a good idea.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#34Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#35Earlier quoted context omitted.
Not all password managers are commercial, closed-source, and cloud-connected. This probably wasn't a main point of yours, but since you mentioned LastPass I felt this should be clarified. I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser. I've been thinking about…
"I ought to at least find a better way than the clipboard, to transfer passwords from the manager app to the browser etc..." With X selection buffers, when you're pasting data the X application you're pasting from gets to run arbitrary code (informed of the destination!) to determine what to send. I've been wanting a password manager that asks me for verification before transferring the data.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#36This is a silly article with an alarmist title. They look at a list of sites she likes on Facebook, then they phish her from one of them. Then she lets them into her house where they look for post-it notes with passwords on them. For a grand finale, they open her garage door. I guess the takeaway here is don't let people that identify themselves as "hackers" through your door and into your home office if you have pas…
The title isn't alarmist. The victim was an ordinary who didn't have a particularly "IoT" home and wasn't a heavy Internet user. They were hacked successfully. It is a useful article as a warning for non-technical people.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#37Earlier quoted context omitted.
"I ought to at least find a better way than the clipboard, to transfer passwords from the manager app to the browser etc..." With X selection buffers, when you're pasting data the X application you're pasting from gets to run arbitrary code (informed of the destination!) to determine what to send. I've been wanting a password manager that asks me for verification before transferring the data.
Don't forget that your clipboard manager also stores the last N things you copied in your clipboard history. I won't lie, it is very convenient for passwords I need to type frequently while sitting on a machine I trust, that doesn't run any remote logging applications and that locks when I'm not there, but it's still obviously a security issue.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#38Earlier quoted context omitted.
Yeah, I don't consider the phishing scams interesting at all. This seems like more of a marketing stunt than anything. And it's borderline not hacking. They actually didn't even do the whole thing themselves. Instead hired a phishing service... To me this is more similar to people dressed as UPS truck drivers going inside an apartment and stealing keys. Or a cashier taking a picture of a customer's credit card. P.S.…
Social Engineering is absolutely hacking. This wasn't a sophisticated example, but it's still a very real threat.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#39Earlier quoted context omitted.
For radio-free hardware, what about a Palm Pilot? Only has IrDA.
A couple of them had Bluetooth. The only 68k-based one with builtin Wi-Fi was the AlphaSmart Dana, a writer's keyboard. You're very very unlikely going to want to type a truly secure (= long) password over and over and over, which you'd need to do in a situation where the browser's password manager is turned off, and/or a website disables password caching anyway. The Palm m5xx series could solve this problem: it had…
3. Ask HN ask HN: Should I ask HN if a Palm Pilot keyboard would be a good password manager?
1 point by i336_ 1 minute ago | flag | past | web | discussRe: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#40Earlier quoted context omitted.
The title isn't alarmist. The victim was an ordinary who didn't have a particularly "IoT" home and wasn't a heavy Internet user. They were hacked successfully. It is a useful article as a warning for non-technical people.
I think it kind of is. There wasn't really hacking involved here, just people taking advantage of an older woman and "pwning" her. Really cringey if you ask me.
If you want to know more, I can recommend The Art of Deception by Kevin Mitnick.