Live data from Hacker News

On Getting Hacked

ahmeto.com

41–50 of 77 posts

Re: On Getting Hacked

#42
post #32

I got hacked late last year. It sucked. Do not recommend. I'm not going to blog about it, but will at least share how I messed up. Maybe it'll help someone else. I was phished through Discord. A CEO that I was friends with was phished prior to me and I let my guard down when someone I put on a pedestal reached out to me. The hacker asked me to review a video game prototype they'd been tinkering with in their spare ti…

what i noticed from you and a couple other similar stories in this thread is that a same email is used at multiple places. Have you looked into email aliases like simplelogin, anonaddy, or anything of that sort? or at the very least, the basic username+alias@domain.tld? this let's you know at least which thing was compromised. of course, I don't recommend doing the same for important services like you banking account…

Honestly, I created the two-email setup at a different time in my life. After the hack, I decided it was easier and more desirable to just use one address. My works speak more for me than a firstname.lastname email now that I've gained some life experience.

I haven't considered looking into other email alias tools. The whole area wasn't something I had put much thought into after getting things the way I wanted a decade prior.

In email, I have used the "+" format in some situations where I'm curious if a third-party is going to leak my contact details. It's not something I use every day, but it is a useful tool, I agree.

The problem with getting a Google account hacked is that Google, by default, really wants to save your passwords for you. So, even though I keep passwords in KeePass, plenty of them ended up remembered inside Chrome, too. Once the hacker compromised the Google account I had to assume every website listed in my password manager needed to be rotated. Plus, I had to change every account that I registered using my "firstname.lastname" email - so I was basically already sold on needing to have to revisit every website I'd ever used.

Re: On Getting Hacked

#43
post #15

Earlier quoted context omitted.

It’s also an issue that extensions like 1Password are _too_ URL-aware, until recently it tried to use heuristics and ignore subdomains for matching credentials. This meant that we used to get a list of almost a hundred options when logging into our AWS infrastructure. No matter which actual domain used. Someone could have used this vulnerability as part of a phishing campaign.

> extensions like 1Password are _too_ URL-aware, until recently it tried to use heuristics and ignore subdomains for matching credentials I've used 1Password for years (Linux+Firefox though, FWIW), and this never happened to me or our family. I did discover though that the autofill basically went by hierarchy in the URI to figure out what to show, so if you specify "example.com" and you're on "login.example.com", you…

It wasn't a considered a bug, it was repeatedly reported to them from us via email and from other customers on their community pages.

Just take a look here for example: https://www.1password.community/discussions/1password/bug-su...

1Password then wrote:

> 1Password currently only suggests items based on the root domain. I can see the value of having 1Password suggest only exact matches based on their subdomain, especially for the use case you have described.

Or take a look here: https://www.1password.community/discussions/1password/sugges...

1Password then wrote:

> As it currently stands, 1Password only matches on the second level domain (i.e. sample.com in your example). While I can't promise anything, this is something we've heard frequently, so I'll share your thoughts with the team.

Now it is:

> You’ll see the item as a suggestion on any page that’s part of the website, including subdomains. The item may also be suggested on related websites known to belong to the same organization.

It's that second sentence which is the problem, they "suggested" by being "smart" items from one AWS domain which ought to have never suggested on another unrelated AWS domain.

In version 8.10 when they added Only fill on this exact host: https://support.1password.com/autofill-behavior/

Re: On Getting Hacked

#44
post #37

Not all too long ago I had someone port out my VOIP number. They had it for a few hours. This was after I had spent extensive effort attempting to secure my digital life. VOIP was SIM-swap resistant sure, but I totally missed that port out requests default to failing open. Thankfully the VOIP operator alerted me and pulled the number back. Then I set a port out code. Who knows how many other holes I have. I lost my s…

Using SMS 2FA has been explicitly deprecated for years. It’s insecure for this and a million other reasons. TOTP is also trivially phishable. I still have my sense of smugness because I use SOTA 2fa.

I wish banks would get this memo. Not only is one of my banks enforcing a maximum password length of 6 NUMBERS (no letters/special characters allowed), but also that high-value transfers are only confirmed via SMS 2FA, even though their own banking app also have a separate 2FA thing that doesn't go through SMS, but it's only used for "low-value" actions...

Re: On Getting Hacked

#45
my younger brother called me once, which was unusual, so i immediately answered. he was crying, which was new to me as well, and told me that our mom's laptop he had been using to game on was hacked, and that he was now being extorted live in a discord call.

asked him to shutdown the laptop immediately and add me to the call, to which he replied, "they sent me our postal code and told me if i told anyone or turned the laptop off, they're going to send someone to hurt me."

that's when i realized why he was panicking so much, to me who was 10 years older that was an obvious scare-tactic, he was a young, naive teenager so he was legitimately scared for his life.

was able to calm him down, he added me to the call, and turned the laptop off. i was surprised that the hackers in question were 3-4 french teenagers, incredibly rude and aggressive. they didn't care that they weren't able to ruffle my feathers, they just constantly asked for bitcoins, said they'd hurt our mom etc.

when i refused and just didn't engage they started posting our mom's tax returns and other files from her laptop, that's when i realized that they did indeed exfiltrate data.

immediately packed my bags and took the next train to meet mom and brother. we spent the afternoon rotating e-banking passwords etc.

while doing this, the hackers did try to login to her paypal and they actually got into my netflix account.

turned the wifi off at home to boot the laptop back up, wanted to try to retrace their steps. i did find out what kind of stealer they used and was able to sleaze my way into a secret discord server they used to organize, but it was temporary and they had already left. so i just wiped the laptop and reinstalled windows.

apparently these guys had promised my brother to optimize his PC so that Fortnite would run better, he let them connect via AnyConnect or TeamViewer, don't exactly remember. they did some legit debloating stuff etc., but also let a stealer run in the background. apparently these guys had spent some weeks in the discord server my brother was in to establish trust.

to this day i haven't felt as much rage again. seeing my young brother in such a distressed state, realizing that all of my mom's data, childhood pictures etc. were stolen made me angry to a point i've never felt, i legitimately wanted to find out who these guys were and hurt them as much as i could. of course we all calmed down again and realized there's nothing we could do other than rotate PWs and observe logins.

police said there's nothing they could do (didn't expect it anyways, but worth a try), discord ignored me when i reported the hacker's accounts. typing this out again makes me angry again, interestingly enough. it's been two years, almost forgot that this ever happened.

Re: On Getting Hacked

#46
post #37

Earlier quoted context omitted.

Using SMS 2FA has been explicitly deprecated for years. It’s insecure for this and a million other reasons. TOTP is also trivially phishable. I still have my sense of smugness because I use SOTA 2fa.

I wish banks would get this memo. Not only is one of my banks enforcing a maximum password length of 6 NUMBERS (no letters/special characters allowed), but also that high-value transfers are only confirmed via SMS 2FA, even though their own banking app also have a separate 2FA thing that doesn't go through SMS, but it's only used for "low-value" actions...

This. My Turkish bank (Garanti BBVA) only works with SMS codes for new logins & payment confirmations, and the app password is 6 digits only, which it also wants (forces) you to change it every now and then because apparently that's a good security measure.

Re: On Getting Hacked

#48
post #37

Not all too long ago I had someone port out my VOIP number. They had it for a few hours. This was after I had spent extensive effort attempting to secure my digital life. VOIP was SIM-swap resistant sure, but I totally missed that port out requests default to failing open. Thankfully the VOIP operator alerted me and pulled the number back. Then I set a port out code. Who knows how many other holes I have. I lost my s…

Using SMS 2FA has been explicitly deprecated for years. It’s insecure for this and a million other reasons. TOTP is also trivially phishable. I still have my sense of smugness because I use SOTA 2fa.

TOTP is not SOTA 2FA. WebAuthn is SOTA 2FA. TOTP can be phished. WebAuthn cannot.

Re: On Getting Hacked

#49
> TikTok deemed I should not have access to my account ever again, and X (formerly Twitter) is delaying a response to my appeal to the suspension, but I have not much hope; I reckon it's gone for good. I may have lost all the personal contacts and content from there, but on the bright side, that has taught and made me see some other things, besides the importance of being a little smarter to not blindly install extensions like my life depended on it.

Well, losing access to both TikTok and X could be considered a bright side as well. But more seriously, isn't it tragic that you can't just blindly assume any piece of OSS isn't malware, anymore?

Re: On Getting Hacked

#50
Great article on reminding the risks of browser extensions. They literally have access to everything within the browser window, from usernames and passwords to bank account details.

Funnily I always tempted by extensions that offer dark more for webpages but never dared to install one.

I do use extensions, but only if they are from well known, respected organisations.

The author was lucky that it was only few compromised social media accounts. It could easily be an empty bank account or stolen identity instead.

Post reply on HN