Live data from Hacker News

Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

bits.blogs.nytimes.com

51–60 of 74 posts

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#51
post #19

Earlier quoted context omitted.

Not all password managers are commercial, closed-source, and cloud-connected. This probably wasn't a main point of yours, but since you mentioned LastPass I felt this should be clarified. I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser. I've been thinking about…

I want a small hardware, non-connected tablet that acts exclusively as a password manager. It connects to the computer I'm using as a USB keyboard device and only "types" a password when I physically tell it to ("yubikey on steroids"). Backups and system updates via flash card with encrypted filesystem. No wifi, no bluetooth, no phone, no ethernet, no other purpose. Edit: heh, that's funny, you edited your comment as…

Hey, I'd be willing to build such a thing. Open source hardware and software and all. Email me at kliment@0xfb.com

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#52
post #45
post #38

Earlier quoted context omitted.

I guess I have a narrower definition of hacking, specifically that it is using technology in a way it wasn't intended. If you ask someone for their credentials and they give them to you, I don't see that as being "a hack," although I guess modern parlance would say the victim "was hacked."

"Hacking" is in everyday parlance not too far from "gaining unauthorised access to a technical system." Social engineering is often a very efficient alternative to rainbow tables, wiretapping, buffer overruns and other technical exploits.

It's often the only or best way too. The more secure a place is the easier it is to get in. People become very trusting. Carry a clipbord and look like you know where you're going and you can walk damn near anywhere.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#53

Earlier quoted context omitted.

The title isn't alarmist. The victim was an ordinary who didn't have a particularly "IoT" home and wasn't a heavy Internet user. They were hacked successfully. It is a useful article as a warning for non-technical people.

I think it kind of is. There wasn't really hacking involved here, just people taking advantage of an older woman and "pwning" her. Really cringey if you ask me.

Criminals who commit identity theft don't care what you find cringey. She (and people like her) are vulnerable, and that's a fact worth knowing.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#56
So "those not hyperconnected" means just normal people?

I don't claim to be hacking proof since I don't control every bit of my data myself, but if someone came into my house they wouldn't find passwords in a notebook or saved passwords in my browsers

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#57

This is a silly article with an alarmist title. They look at a list of sites she likes on Facebook, then they phish her from one of them. Then she lets them into her house where they look for post-it notes with passwords on them. For a grand finale, they open her garage door. I guess the takeaway here is don't let people that identify themselves as "hackers" through your door and into your home office if you have pas…

>she lets them into her house

She didn't need to though, they could have entered through the garage door while she was away.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#59
post #33

Earlier quoted context omitted.

For radio-free hardware, what about a Palm Pilot? Only has IrDA.

A couple of them had Bluetooth. The only 68k-based one with builtin Wi-Fi was the AlphaSmart Dana, a writer's keyboard. You're very very unlikely going to want to type a truly secure (= long) password over and over and over, which you'd need to do in a situation where the browser's password manager is turned off, and/or a website disables password caching anyway. The Palm m5xx series could solve this problem: it had…

Just make something like a usb Rubber Ducky with a couple buttons and a screen. Plug it in, scroll to password, hit "type it", and it types it in. Could probably make one for about $40. Arduino Leonardo, LCD Shield, and the leonardo keyboard libraries. Could even have it as a full password generator too.

Re: Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected

#60
An interesting piece and definitely has some merit depending on the audience. False sense of security. Bad habits. This is kind of an exaggerated approach to teaching.

For anybody who doubts that "gaining physical access" automatically disqualifies the results, let me share a recent uptick in a specific con in my area that could very well be adapted as a template to other unsuspecting areas:

Two men in hard-hats and workman clothes approach a home, clipboard in hand, and claim to be with the "power company" and want to have a moment of time to talk about some trees close to the power lines. It's a right of way issue. They ask for the resident to come out and take a look with them. All seems pretty normal.

The talker gets the person or couple's attention while the other makes a quick excuse to go back to the truck out in front of the house. The talker carries on about how they're going to take care of the trees at no cost to the residents, and they act very cordial overall. Meanwhile, the partner has gone into the home via the front door which was left unlocked, goes for the most likely targets of value (ex: jewelry). The partner goes to the truck while talker wraps up and leaves. By the time the residents notice anything is amiss, the duo are long gone.

Trust-cons are a huge issue for a large portion of the population, in my opinion. Being prepared to be charmed while being fleeced is not how normal people go about their day.

Post reply on HN