On Getting Hacked
41–50 of 77 posts
Re: On Getting Hacked
#42I got hacked late last year. It sucked. Do not recommend. I'm not going to blog about it, but will at least share how I messed up. Maybe it'll help someone else. I was phished through Discord. A CEO that I was friends with was phished prior to me and I let my guard down when someone I put on a pedestal reached out to me. The hacker asked me to review a video game prototype they'd been tinkering with in their spare ti…
what i noticed from you and a couple other similar stories in this thread is that a same email is used at multiple places. Have you looked into email aliases like simplelogin, anonaddy, or anything of that sort? or at the very least, the basic username+alias@domain.tld? this let's you know at least which thing was compromised. of course, I don't recommend doing the same for important services like you banking account…
I haven't considered looking into other email alias tools. The whole area wasn't something I had put much thought into after getting things the way I wanted a decade prior.
In email, I have used the "+" format in some situations where I'm curious if a third-party is going to leak my contact details. It's not something I use every day, but it is a useful tool, I agree.
The problem with getting a Google account hacked is that Google, by default, really wants to save your passwords for you. So, even though I keep passwords in KeePass, plenty of them ended up remembered inside Chrome, too. Once the hacker compromised the Google account I had to assume every website listed in my password manager needed to be rotated. Plus, I had to change every account that I registered using my "firstname.lastname" email - so I was basically already sold on needing to have to revisit every website I'd ever used.
Re: On Getting Hacked
#43Earlier quoted context omitted.
It’s also an issue that extensions like 1Password are _too_ URL-aware, until recently it tried to use heuristics and ignore subdomains for matching credentials. This meant that we used to get a list of almost a hundred options when logging into our AWS infrastructure. No matter which actual domain used. Someone could have used this vulnerability as part of a phishing campaign.
> extensions like 1Password are _too_ URL-aware, until recently it tried to use heuristics and ignore subdomains for matching credentials I've used 1Password for years (Linux+Firefox though, FWIW), and this never happened to me or our family. I did discover though that the autofill basically went by hierarchy in the URI to figure out what to show, so if you specify "example.com" and you're on "login.example.com", you…
Just take a look here for example: https://www.1password.community/discussions/1password/bug-su...
1Password then wrote:
> 1Password currently only suggests items based on the root domain. I can see the value of having 1Password suggest only exact matches based on their subdomain, especially for the use case you have described.
Or take a look here: https://www.1password.community/discussions/1password/sugges...
1Password then wrote:
> As it currently stands, 1Password only matches on the second level domain (i.e. sample.com in your example). While I can't promise anything, this is something we've heard frequently, so I'll share your thoughts with the team.
Now it is:
> You’ll see the item as a suggestion on any page that’s part of the website, including subdomains. The item may also be suggested on related websites known to belong to the same organization.
It's that second sentence which is the problem, they "suggested" by being "smart" items from one AWS domain which ought to have never suggested on another unrelated AWS domain.
In version 8.10 when they added Only fill on this exact host: https://support.1password.com/autofill-behavior/
Re: On Getting Hacked
#44Not all too long ago I had someone port out my VOIP number. They had it for a few hours. This was after I had spent extensive effort attempting to secure my digital life. VOIP was SIM-swap resistant sure, but I totally missed that port out requests default to failing open. Thankfully the VOIP operator alerted me and pulled the number back. Then I set a port out code. Who knows how many other holes I have. I lost my s…
Using SMS 2FA has been explicitly deprecated for years. It’s insecure for this and a million other reasons. TOTP is also trivially phishable. I still have my sense of smugness because I use SOTA 2fa.
Re: On Getting Hacked
#45asked him to shutdown the laptop immediately and add me to the call, to which he replied, "they sent me our postal code and told me if i told anyone or turned the laptop off, they're going to send someone to hurt me."
that's when i realized why he was panicking so much, to me who was 10 years older that was an obvious scare-tactic, he was a young, naive teenager so he was legitimately scared for his life.
was able to calm him down, he added me to the call, and turned the laptop off. i was surprised that the hackers in question were 3-4 french teenagers, incredibly rude and aggressive. they didn't care that they weren't able to ruffle my feathers, they just constantly asked for bitcoins, said they'd hurt our mom etc.
when i refused and just didn't engage they started posting our mom's tax returns and other files from her laptop, that's when i realized that they did indeed exfiltrate data.
immediately packed my bags and took the next train to meet mom and brother. we spent the afternoon rotating e-banking passwords etc.
while doing this, the hackers did try to login to her paypal and they actually got into my netflix account.
turned the wifi off at home to boot the laptop back up, wanted to try to retrace their steps. i did find out what kind of stealer they used and was able to sleaze my way into a secret discord server they used to organize, but it was temporary and they had already left. so i just wiped the laptop and reinstalled windows.
apparently these guys had promised my brother to optimize his PC so that Fortnite would run better, he let them connect via AnyConnect or TeamViewer, don't exactly remember. they did some legit debloating stuff etc., but also let a stealer run in the background. apparently these guys had spent some weeks in the discord server my brother was in to establish trust.
to this day i haven't felt as much rage again. seeing my young brother in such a distressed state, realizing that all of my mom's data, childhood pictures etc. were stolen made me angry to a point i've never felt, i legitimately wanted to find out who these guys were and hurt them as much as i could. of course we all calmed down again and realized there's nothing we could do other than rotate PWs and observe logins.
police said there's nothing they could do (didn't expect it anyways, but worth a try), discord ignored me when i reported the hacker's accounts. typing this out again makes me angry again, interestingly enough. it's been two years, almost forgot that this ever happened.
Re: On Getting Hacked
#46Earlier quoted context omitted.
Using SMS 2FA has been explicitly deprecated for years. It’s insecure for this and a million other reasons. TOTP is also trivially phishable. I still have my sense of smugness because I use SOTA 2fa.
I wish banks would get this memo. Not only is one of my banks enforcing a maximum password length of 6 NUMBERS (no letters/special characters allowed), but also that high-value transfers are only confirmed via SMS 2FA, even though their own banking app also have a separate 2FA thing that doesn't go through SMS, but it's only used for "low-value" actions...
Re: On Getting Hacked
#47What was the Chrome extension?
Re: On Getting Hacked
#48Not all too long ago I had someone port out my VOIP number. They had it for a few hours. This was after I had spent extensive effort attempting to secure my digital life. VOIP was SIM-swap resistant sure, but I totally missed that port out requests default to failing open. Thankfully the VOIP operator alerted me and pulled the number back. Then I set a port out code. Who knows how many other holes I have. I lost my s…
Using SMS 2FA has been explicitly deprecated for years. It’s insecure for this and a million other reasons. TOTP is also trivially phishable. I still have my sense of smugness because I use SOTA 2fa.
Re: On Getting Hacked
#49Well, losing access to both TikTok and X could be considered a bright side as well. But more seriously, isn't it tragic that you can't just blindly assume any piece of OSS isn't malware, anymore?
Re: On Getting Hacked
#50Funnily I always tempted by extensions that offer dark more for webpages but never dared to install one.
I do use extensions, but only if they are from well known, respected organisations.
The author was lucky that it was only few compromised social media accounts. It could easily be an empty bank account or stolen identity instead.