Live data from Hacker News

Break into my email: get $10,000. Here is my username and password.

strongwebmail.com

31–40 of 61 posts

Re: Break into my email: get $10,000. Here is my username and password.

#32
post #5

"Here’s the thing, in order to get into a StrongWebmail account, the account owner must receive a verification call on their phone. This means that even if your password is stolen, the thief can’t access your email because they don’t have access to your telephone." Great. Users will love receiving calls at all hours as script kiddies in Russia try to log in to their accounts. "Break into my email: get $10,000. Here i…

The CEO username and password work for me. I've checked the obvious stuff and they have that covered, so it won't be an easy $10,000. But I'm sure no system is 100% infallible :)

Re: Break into my email: get $10,000. Here is my username and password.

#33
Chase Bank does something similar. If your computer isn't cookied, then you are required to perform some sort of identity authentication (voice, text, email, etc). I'm surprised more important utilities like email don't follow this concept... it would at least weed out the brute force attacks.

Re: Break into my email: get $10,000. Here is my username and password.

#34
post #9

Ten THOUSAND dollars. That's literally, like, an entire FRACTION of what an application penetration test costs! They must really be serious! [ quick edit: I really hate talking about numbers here, because if you have some bootstrapped YC-style company and you're worried about security, I'd love to think you could reach out to us and not have us try to get into you for tens of thousands of dollars --- but for an actua…

Low quality distributed penetration testing is cheap :).

And totally ineffective.

Re: Break into my email: get $10,000. Here is my username and password.

#35
post #9

Ten THOUSAND dollars. That's literally, like, an entire FRACTION of what an application penetration test costs! They must really be serious! [ quick edit: I really hate talking about numbers here, because if you have some bootstrapped YC-style company and you're worried about security, I'd love to think you could reach out to us and not have us try to get into you for tens of thousands of dollars --- but for an actua…

Right, hence crowdsourcing.

I guess my point is: if you find a security hole in this service, why would you give it up for $10,000?

Re: Break into my email: get $10,000. Here is my username and password.

#36
post #4

This is out of my field, but how do you all think this will be compromised? My guess would be by spoofing the CEO's home IP & cookie to bypass the verification, based on this paragraph from the site: "Plus, users only need to receive a verification call when they are logging in from an unrecognized computer. When logging in from a home or work computer, a cookie can be stored so that no verification call is required.…

This is basically the same thing as MobilePass, which hasn't been broken to my knowledge, so I wouldn't expect a direct attack. Your suggestion is a possibility.

There are also a bunch of unknowns. Are there any direct attacks (SQL injection, privilege escalation, etc) on the StrongWebmail site? What sort of datacenter is it in (alchemy.net, which are HIPAA compliant, which should be pretty safe)? Are the challenges generated in a cryptographically secure manner? How secure is the CEO's home machine? Does the CEO purge cookies at the end of the session? Does it count if I can manage to redirect his e-mail elsewhere instead (which can be done with well-known DNS exploits)?

Part of the defense here is that the prize is small enough that it's not worth trying many of the more elaborate tricks (like attempting to break the PRNG for the keys, if any).

Re: Break into my email: get $10,000. Here is my username and password.

#39
This is gonna end in tears :P And it will not the hackers... I love these publicity stunts that claim: "We're unhackable! Best security E-V-A-H!".

BTW, has anyone heard of those awesome Medeco locks? I heard that they can't be picked. That is so cool!

Re: Break into my email: get $10,000. Here is my username and password.

#40
post #9

Ten THOUSAND dollars. That's literally, like, an entire FRACTION of what an application penetration test costs! They must really be serious! [ quick edit: I really hate talking about numbers here, because if you have some bootstrapped YC-style company and you're worried about security, I'd love to think you could reach out to us and not have us try to get into you for tens of thousands of dollars --- but for an actua…

So, based on the edit, how should small startups (or Open Source projects) reach out to security pros?

Some Open Source projects have millions of users, and so security is obviously a concern...I've noticed in our own project that we occasionally get penetration testing reports from security companies out of the blue (I guess because Webmin is high profile enough, and is potentially dangerous enough, to be on everyone's radar), but how would one get a new project or product onto the radar? Obviously, Open Source projects generally don't have 10k*N dollars to spend.

I ask because I've recently thought of doing something along these lines for our own stuff. Not because I want publicity, but because we really want to know about any issues.

Post reply on HN