Earlier quoted context omitted.
The title isn't alarmist. The victim was an ordinary who didn't have a particularly "IoT" home and wasn't a heavy Internet user. They were hacked successfully. It is a useful article as a warning for non-technical people.
I think it kind of is. There wasn't really hacking involved here, just people taking advantage of an older woman and "pwning" her. Really cringey if you ask me.
Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
41–50 of 74 posts
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#42Summary: Hackers send grandmother phishing mail. Grandmother enter her email address and password. Hackers go into house of Grandmother. Hackers change settings on router and and television of grandmother.
Yeah, I don't consider the phishing scams interesting at all. This seems like more of a marketing stunt than anything. And it's borderline not hacking. They actually didn't even do the whole thing themselves. Instead hired a phishing service... To me this is more similar to people dressed as UPS truck drivers going inside an apartment and stealing keys. Or a cashier taking a picture of a customer's credit card. P.S.…
Physically breaking in is a real threat. Now break-ins risk digital breaches as well as the old standards. Just because it involves being onsite doesn't mean it isn't a meaningful threat, and now it's not limited to just the artifacts that are stolen.
In fact, "standard" protocol in response to a physical home breakin should probably include a digital "audit."
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#43This is a silly article with an alarmist title. They look at a list of sites she likes on Facebook, then they phish her from one of them. Then she lets them into her house where they look for post-it notes with passwords on them. For a grand finale, they open her garage door. I guess the takeaway here is don't let people that identify themselves as "hackers" through your door and into your home office if you have pas…
This should be a wake up call to the have-nots: You aren't safe just because you don't post on Facebook and you don't use the computer. Just because you don't drive doesn't mean you can't be hit by a car.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#44Burglars have always targeted items that are valuable to them. Easy to sell, gets a good price, etc.
Now we have digital assets in the home, and burglars are going to focus on those things too. For most of the population, and probably many of "us", physical access to those digital assets isn't particularly secure. And to have those assets "taken" today is much more far reaching than to have lost a stereo or checkbook.
Just because the attacker had to get off his couch and go somewhere shouldn't minimize this threat. "Physical access means's you're pwned" is a true statement.
One thing I do at home, for example, is to use full disk encryption on my laptop, and hibernate it when I leave. So that if someone steals it, it's just a plastic brick. For exactly the scenario described in the article.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#45Earlier quoted context omitted.
Social Engineering is absolutely hacking. This wasn't a sophisticated example, but it's still a very real threat.
I guess I have a narrower definition of hacking, specifically that it is using technology in a way it wasn't intended. If you ask someone for their credentials and they give them to you, I don't see that as being "a hack," although I guess modern parlance would say the victim "was hacked."
Social engineering is often a very efficient alternative to rainbow tables, wiretapping, buffer overruns and other technical exploits.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#46This is a silly article with an alarmist title. They look at a list of sites she likes on Facebook, then they phish her from one of them. Then she lets them into her house where they look for post-it notes with passwords on them. For a grand finale, they open her garage door. I guess the takeaway here is don't let people that identify themselves as "hackers" through your door and into your home office if you have pas…
I'd disagree, I think is an excellent example of people who think they don't need to worry about security because they aren't on the Internet very much. It was all pretty mundane I agree, right up until they had her power of attorney and social security number. This should be a wake up call to the have-nots: You aren't safe just because you don't post on Facebook and you don't use the computer. Just because you don't…
They only got these after she let them into her house and gave them physical access to her computer. Of course it's only common sense that anyone that is allowed into your home and onto your computer can "pwn" you and worse - hacker or not. That's why 99.9% of people, including this woman, wouldn't allow strangers into their home and give them unfettered physical access to their computer.
The article title implies that they were able to "pwn" her through "hacking". The only mildly interesting they did in this regard was the spear-phishing attack based on her Facebook likes.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#47This is a silly article with an alarmist title. They look at a list of sites she likes on Facebook, then they phish her from one of them. Then she lets them into her house where they look for post-it notes with passwords on them. For a grand finale, they open her garage door. I guess the takeaway here is don't let people that identify themselves as "hackers" through your door and into your home office if you have pas…
I'd disagree, I think is an excellent example of people who think they don't need to worry about security because they aren't on the Internet very much. It was all pretty mundane I agree, right up until they had her power of attorney and social security number. This should be a wake up call to the have-nots: You aren't safe just because you don't post on Facebook and you don't use the computer. Just because you don't…
If I have a vendata against you, I can break into your home and setup keyloggers, hidden video/audio recorders that "call home" or even allow me to "dial in" and listen in. I don't need your stinking post-it notes and I won't even have to be in a rush. (http://www.amazon.com/dp/B00CIXAF8O/ref=wl_it_dp_o_pC_S_ttl?...)
The only thing this pawnage verified for me is that there are a lot of people with malware running on their computers and these same people are susceptible to phishing scams.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#48Earlier quoted context omitted.
"I ought to at least find a better way than the clipboard, to transfer passwords from the manager app to the browser etc..." With X selection buffers, when you're pasting data the X application you're pasting from gets to run arbitrary code (informed of the destination!) to determine what to send. I've been wanting a password manager that asks me for verification before transferring the data.
Don't forget that your clipboard manager also stores the last N things you copied in your clipboard history. I won't lie, it is very convenient for passwords I need to type frequently while sitting on a machine I trust, that doesn't run any remote logging applications and that locks when I'm not there, but it's still obviously a security issue.
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#49So many people here are dismissing this as unsophisticated. Burglars have always targeted items that are valuable to them. Easy to sell, gets a good price, etc. Now we have digital assets in the home, and burglars are going to focus on those things too. For most of the population, and probably many of "us", physical access to those digital assets isn't particularly secure. And to have those assets "taken" today is mu…
Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
#50Earlier quoted context omitted.
Not all password managers are commercial, closed-source, and cloud-connected. This probably wasn't a main point of yours, but since you mentioned LastPass I felt this should be clarified. I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser. I've been thinking about…
I want a small hardware, non-connected tablet that acts exclusively as a password manager. It connects to the computer I'm using as a USB keyboard device and only "types" a password when I physically tell it to ("yubikey on steroids"). Backups and system updates via flash card with encrypted filesystem. No wifi, no bluetooth, no phone, no ethernet, no other purpose. Edit: heh, that's funny, you edited your comment as…