Live data from Hacker News

How the Syrian Electronic Army Hacked The Onion

theonion.github.io

51–60 of 68 posts

Re: How the Syrian Electronic Army Hacked The Onion

#51
post #24
post #22

Earlier quoted context omitted.

I agree with this point. I retype my user information, even while logged in, at least a few times a week.

That's odd because I never do. I'm using two-factor and I only have to retype login information when that expires (approximately 30 days I believe.) Also, someone did phish my Google cookies and Google immediately shutdown my account and made me type in something from a text to reactivate my account. Overall I'm pretty happy with both of those circumstances.

This happens to me weekly. One problem in my case is I have three Google accounts (1 work, 1 Personal Gmail, 1 Youtube).

Some of the accounts don't work in every context, i.e. the pre-Google YouTube account doesn't seem to work for displaying public Google docs embedded PDFs. Sadly the accounts can be linked but not merged[1] which means I'm stuck.

[1]http://support.google.com/accounts/bin/answer.py?hl=en&a...

Re: How the Syrian Electronic Army Hacked The Onion

#52
post #9

I often think about creating a browser and email plugin/extension to help with this: - Look at all link tags. - If it looks like a URL (has a scheme at the beginning, or something which resembles a hostname, or a bunch of path or query parameters), inspect the actual link. - If they have different hosts, warn the user, and perhaps give them the option of just visiting what the contents of the link tag say (rather tha…

I would just be happy if clicking any link in an email just popped up dialog first with "Do you want to go to the following URL" with the real URL. I always copy URLs from emails and paste into the browser to be sure I'm getting the URL I think I am, and this is basically just giving me the same preview. For less qualified users, maybe it could bold/highlight the domain name (stripping the subdomains where all the phishing magic happens) and ask "are you sure you want to go to phishingdomain.com".

Re: How the Syrian Electronic Army Hacked The Onion

#53
post #18
post #3

> "Please read the following article for its importance" This immediately hit my brain's bayesian classifier like a ton of bricks. Or as the saying goes, "If spammers ever learn proper English, god help us all." * the English is actually proper, but the wording is unusual

It doesn't work for spear phishing, but for wide-ranging hits the broken english is often on purpose: http://research.microsoft.com/pubs/167719/whyfromnigeria.pdf :: http://www.onthemedia.org/2012/aug/31/why-nigerian-email-sca... tldr: you have a lower number of leads but a higher conversion rate from those that do respond.

I can see the logic here, but for something that's a one-and-done "click this link and type in your credentials," I honestly think good spelling would add to the legitimacy. So in The Onion's case I think it's just a matter of the attackers not being good at English; if they were, I feel their success would increase a bit.

Re: How the Syrian Electronic Army Hacked The Onion

#54

Wait, did did The Onion actually get hacked? I just assumed that was a joke. Now I'm confused...

Notice that the Onion Tech Blog is an entirely new site with a single post. Presumably because if this was posted on theonion.com no one would've believed it.

Re: How the Syrian Electronic Army Hacked The Onion

#55
I'm not sure what happened here:

>... which asked for Google Apps credentials before redirecting to the Gmail inbox.

followed by:

>Coming from a trusted address, many staff members clicked the link, but most refrained from entering their login credentials.

Does this mean "[asking] for Google Apps credentials" should be read as "put in their Google username and password", or should it be "gave the site OAuth access to their Google account"?

I'm a bit curious, because it sounds like they set up a Google Apps app that sent phishing emails from the first-round-phished accounts to others in the company, so it looked more legit, but this second-round email was not the same as the first. I haven't heard of that trick before, but it's clever, and probably hard to work around.

But if they actually entered their user/pass, there's an easy solution. USE A PASSWORD MANAGER. Kills phishing dead, since it won't auto-fill on the wrong domain.

Re: How the Syrian Electronic Army Hacked The Onion

#56
post #22
post #12

Google requiring you to enter your password at random times for random things (e.g. to read a Google Groups message) seems like one contributing factor, since people treat those prompts as routine noise, and are less likely to investigate such a common occurrence too deeply.

I agree with this point. I retype my user information, even while logged in, at least a few times a week.

I never re-type my user information. I don't even know what it is.

Whenever I create a new password for a website, I make sure it's random, and I make sure I can't remember it. I leave that job up to Firefox's password save mechanism.

Whenever I REALLY need a password, I go to the text file I pasted it in when I created it. Or extract it from within the firefox preferences.

Case in point. If a certain login URL I am familiar with doesn't know my password I am suspicious already.

Re: How the Syrian Electronic Army Hacked The Onion

#57

An interesting story. > The email addresses for your twitter accounts should be on a system that is isolated from your organization’s normal email. This will make your Twitter accounts virtually invulnerable to phishing (providing that you’re using unique, strong passwords for every account). That doesn't make a lot of sense. Sure, now your twitter account is somewhat protected against phishing (I think 'invulernable…

Our point there was this: the type of phishing that caught us was pretty casual, and aimed at users who weren't very technically sophisticated, and those users shouldn't have had access to our twitter accounts. The proposed solution is certainly pretty drastic, but when it comes to securing twitter accounts, there aren't a lot of options. The safest one I can see is to connect the accounts to an email address that is…

There's a potential non-technical problem with that solution, though - what happens when the person who controls that email address leaves the company, especially if they leave on bad terms? I've had to deal with figuring out the mystery email that was connected to a corporate social media account, and it was a hellish bureaucratic nightmare to find the social media intern from three summers ago who had the password for the throwaway email. If it had been an email from our corporate domain, it would have been a lot easier to gain control of it again.

(What I would have given for a physical, printed list of social media accounts, associated emails, and passwords hidden in a file drawer somewhere.)

Re: How the Syrian Electronic Army Hacked The Onion

#58
post #9

I often think about creating a browser and email plugin/extension to help with this: - Look at all link tags. - If it looks like a URL (has a scheme at the beginning, or something which resembles a hostname, or a bunch of path or query parameters), inspect the actual link. - If they have different hosts, warn the user, and perhaps give them the option of just visiting what the contents of the link tag say (rather tha…

I believe Thunderbird's phishing detection does something along the lines of matching link text with link destinations. Mostly noticed it because mail from Mozilla tend to trip it...

It also (by default) disables scripts in mail anyway, so onclick events aren't a problem. In fact, I would be surprised if any mail client enables script by default; that just seems like a horribly bad idea.

Re: How the Syrian Electronic Army Hacked The Onion

#60
post #11

The points in this blog post are good...but how about something more basic: Never log in after clicking through an email link

Why would you ever click on an e-mail link?

No wonder! I was wondering what the problem was, and it appears to be PEBKAC.

Post reply on HN