Live data from Hacker News

How the Syrian Electronic Army Hacked The Onion

theonion.github.io

41–50 of 68 posts

Re: How the Syrian Electronic Army Hacked The Onion

#42
post #12

Google requiring you to enter your password at random times for random things (e.g. to read a Google Groups message) seems like one contributing factor, since people treat those prompts as routine noise, and are less likely to investigate such a common occurrence too deeply.

That's a really good point. It happened with me a few times, especially while clicking on some search results pointing to Google Groups. Now I'm wondering if any of those were actually phishing attempts, because it's sometimes really easily to overlook what the real domain of the search result is.

Re: How the Syrian Electronic Army Hacked The Onion

#44
post #9

I often think about creating a browser and email plugin/extension to help with this: - Look at all link tags. - If it looks like a URL (has a scheme at the beginning, or something which resembles a hostname, or a bunch of path or query parameters), inspect the actual link. - If they have different hosts, warn the user, and perhaps give them the option of just visiting what the contents of the link tag say (rather tha…

People who fall for attacks like this don't install protective extensions, or if they do, they become complacent assuming that those extensions will always protect them.

Re: How the Syrian Electronic Army Hacked The Onion

#45
post #24
post #22

Earlier quoted context omitted.

I agree with this point. I retype my user information, even while logged in, at least a few times a week.

That's odd because I never do. I'm using two-factor and I only have to retype login information when that expires (approximately 30 days I believe.) Also, someone did phish my Google cookies and Google immediately shutdown my account and made me type in something from a text to reactivate my account. Overall I'm pretty happy with both of those circumstances.

Good point; I wonder how many people take that approach. I personally tend to log out of Gmail after I read my email, which signs me out of my Google Account fairly regularly. But maybe that's an unusual use pattern.

Re: How the Syrian Electronic Army Hacked The Onion

#46
post #33
post #2

One more reason to use 2FA on your Google Apps account.

One problem I have with the current 2FA on Google Apps is that there is no way to enforce 2FA for all users before everyone sets up their mobile device. If you've set the requirement for all to have 2FA, then new users can never log in. You're then left in this limbo of some with/some without 2FA, and unless you actively pursue those without it setup, you can never change that system wide setting in the control panel…

This is a serious problem, but they do have a workaround. You put new users in an "exception group" that doesn't require two factor auth. Then after they set them up you take them out of the group. It's better than nothing:

http://support.google.com/a/bin/answer.py?hl=en&answer=2...

Re: How the Syrian Electronic Army Hacked The Onion

#49
> The email addresses for your twitter accounts should be on a system that is isolated from your organization’s normal email. This will make your Twitter accounts virtually invulnerable to phishing (providing that you’re using unique, strong passwords for every account).

This, of course, is an artefact of the well-known, old problem of your email being the single point of failure for your entire online identity.

Google might be able to do something to help here: Surely, they can detect with high reliability if a given email contains a password reset link, and trigger an extra challenge. I'm not sure what it should be, as obviously the account password isn't going to cut it. It could really just be a very short PIN-style code for opening "sensitive" email.

Re: How the Syrian Electronic Army Hacked The Onion

#50
post #19
post #15

Earlier quoted context omitted.

2FA is great, but it wouldn't save you here if you ask it to remember you for 30 days.

It would have stopped someone from using a phished GApps credential from logging in to Google using it, though. It sounds like one prong of the attack was to gain access to one employee's email, then use that account to send phishing emails to other employees. 2FA would have stopped that.

I wonder if it would be possible to phish 2factor while you're at it... Something like:

1- get target to enter google credentials

2- log into target's account using those credentials with a proxy/controlled IP that shows up nearby in geoip DBs

3- display a credible message, asking for 2factor code (something something DHCP something something more buzzwords - dummy mode on)

Any reason this wouldn't work?

Post reply on HN