Live data from Hacker News

I was seven words away from being spear-phished

robertheaton.com

31–40 of 187 posts

Re: I was seven words away from being spear-phished

#31
post #14
post #6

It's always nice to get a good healthy dose of paranoia in the morning. This makes me think back to how my sec professor had a separate system that he'd use to access his online banking.

To be honest, that's probably overboard. You're pretty much never liable for fraudulent fiat transactions. Crypto on the other hand...

I've heard of at least one case where money was transferred out of someone's bank account through online banking and he was held liable. The user claimed fraud but since the intruder used his username and password the bank refused to refund the money claiming he had a responsibility to secure his username and password.

Re: I was seven words away from being spear-phished

#32

I don't understand the point of using compromised Cambridge accounts for this. All they wanted people to do was to just click on a link. They could have easily registered some legitimate sounding domain name and linked to that instead. It wouldn't be unusual at all for an academic organisation to have a separate site.

It's the cyber-version of speaking with a British accent.

Re: I was seven words away from being spear-phished

#33
The specifics of this - the request to judge a prize one is clearly unqualified for - are we as software engineers particularly vulnerable to? Most people would, I think, conclude "this is fake, because why would I be asked to do this?". But I often think that as software engineers we fancy ourselves to have more insight into other fields than we really do. Does this ring true to anyone else?

Re: I was seven words away from being spear-phished

#34
This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english!

If it hasn't already been tried, perhaps it's worth building a spam-blocker which checks for bad grammar and increases the spam score for every mistake found.

Re: I was seven words away from being spear-phished

#35
post #26

It's impossible to overestimate the power of expectations to create trust (even in the face of contrary indications). This just almost happened to me this week: A couple of days ago I wrote an email to a friend I hadn't been in touch with for several years. A day later I got a message from him on Facebook with what looked like a YouTube link and the cryptic message, "It's you?" I didn't want to see myself on a random…

A few days ago, I also received the same message from a friend with a link to a fake youtube page, but unlike you, I actually clicked it despite intuitively knowing that it was malicious. Seemed like a "regular" phishing attempt but I now wonder if it is more than that, having read this article.

Re: I was seven words away from being spear-phished

#36

The specifics of this - the request to judge a prize one is clearly unqualified for - are we as software engineers particularly vulnerable to? Most people would, I think, conclude "this is fake, because why would I be asked to do this?". But I often think that as software engineers we fancy ourselves to have more insight into other fields than we really do. Does this ring true to anyone else?

It could be that they're setting up some new category related to tech or something, that would probably be my first attempt to rationalize why they sent the request to me. However, I think that a few minutes later I would've thought "but why would they ask an engineer and not an academic who has done research into this particular technology's contributions to economics?".

But, yes, I believe that the fact that software is transforming so much stuff all the time and we developers get to work with experts from all kinds of fields if we're lucky like agriculture, medicine, geology, finance and what not can give us a false sense of actually being an authority on any of the things we write software for.

Re: I was seven words away from being spear-phished

#37
I suppose it's easy to "Monday Morning Quarterback" this one, especially after we now know it's a hoax, but honestly this is more fuel on the fire of: Never respond to random people on the internet asking you for information or to do something. Random people knocking on your door are almost always selling something, and random people contacting you over the Internet are almost always scammers.

The story could have ended at "I wouldn’t say I’m an “expert” in economics exactly". Then why are you going and doing what this rando is asking you to do? Deep six the E-mail and move on with your life.

Re: I was seven words away from being spear-phished

#39
post #14

Earlier quoted context omitted.

To be honest, that's probably overboard. You're pretty much never liable for fraudulent fiat transactions. Crypto on the other hand...

I've heard of at least one case where money was transferred out of someone's bank account through online banking and he was held liable. The user claimed fraud but since the intruder used his username and password the bank refused to refund the money claiming he had a responsibility to secure his username and password.

>since the intruder used his username and password the bank refused to refund the money claiming he had a responsibility to secure his username and password

what jurisdiction is this? this seems like the worse consumer protection law ever.

Re: I was seven words away from being spear-phished

#40

This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn'…

I read in the past that this was intentional - it's a filter to ensure that people who are inclined to note detail pass up on the offer, meaning they only get the most likely prospects to be ripped off.
Post reply on HN