Live data from Hacker News

How are cyber criminals rolling in 2025?

vin01.github.io

71–80 of 97 posts

Re: How are cyber criminals rolling in 2025?

#71
post #44

Earlier quoted context omitted.

Have you tried getting ticketing support from Ticketmaster? Even a sketchy phone number is better than no option at all…

I don't mean reaching for support. I mean setting up a scam like this. It seems so bottom of the barrel scummy, creative too, but mostly scummy. Imagine you have the creativity and criminal energy to conceptualize and operate something like this (and the rat tail of justice evasion, laundering money, etc). It seems so much easier to make money in the honest economy. Unless of course you're operating for a rogue state…

People do this sort of thing specifically because the "honest" economy is not really that great except for a small percentage of people.

Re: How are cyber criminals rolling in 2025?

#72
post #42

john wick site:europa.eu https://www.google.com/search?q=john+wick+site%3Aeuropa.eu&h... gta 5 site:europa.eu https://www.google.com/search?q=gta+5+site%3Aeuropa.eu&hl=en Watch full site:europa.eu https://www.google.com/search?q=Watch+full+site%3Aeuropa.eu&...

When clicked, all show: page not found So, fixed now?

They're usually designed so only Google sees it. It's for SEO, not to trick people.

Re: How are cyber criminals rolling in 2025?

#73
post #33

Earlier quoted context omitted.

Exactly. And when you try and help these people and explain that you didn't actually call Ticketmaster support they will tell you that they found the phone number on the official Ticketmaster website and Google said it was a verified link. Here's a real example from the same thing happening on FB (don't call that number) https://i.redd.it/w9htjqflgjle1.jpeg

Completely unrelated tangent: Jesus Christ Reddit is such a cesspit. Tried tapping that link on mobile, got a screen to view the corresponding post. Tapped it, and I got taken to the App Store. No thanks, force quit the App Store and go back. Now I get a full screen notice on the original Reddit tab saying “didn’t go where you expected? Next time try the long press!” With instructions to not use private browsing and…

> Tried tapping that link on mobile, got a screen to view the corresponding post. Tapped it, and I got taken to the App Store.

It's obnoxious, but if you really want to view the post you can switch the screenshot page to desktop mode, and the "View post" button shouldn't redirect to the App Store. The result isn't pretty but it's readable in a pinch.

(They're still not desperate enough to track the UA and detect the switch.)

Re: How are cyber criminals rolling in 2025?

#74

Among the common vulnerabilities listed: > Outdated Wordpress plugins and CMS systems No surprise, having worked in edu the following scenario was very common: 1) Researcher gets a grant for a project 2) Grad student sets up a Drupal site for the project 3) Things are maintained and updated for a couple of years 4) Grant runs out, project wraps up, student graduates, everyone forgets about the server which sits unatt…

At my old university ~15 years ago, all IPs of all computers were public IPV4 addresses . Any computer plugged in to any ethernet port on campus was given such a "quasi-static" IP address. All normal ports were open - ssh, http(s), you name it. It was the OG zero trust architecture.

I used to have the public IP address of the computer in my dorm room memorized. It's been 20 years, and I still remember it started with 128.211.

Re: How are cyber criminals rolling in 2025?

#75
post #45
post #44

Earlier quoted context omitted.

I don't mean reaching for support. I mean setting up a scam like this. It seems so bottom of the barrel scummy, creative too, but mostly scummy. Imagine you have the creativity and criminal energy to conceptualize and operate something like this (and the rat tail of justice evasion, laundering money, etc). It seems so much easier to make money in the honest economy. Unless of course you're operating for a rogue state…

You've got a shocking amount of faith in the honest economy for this moment in time

"This moment" that has lasted about 22 years or so. There were two good runs if you had money to invest, but whatever.

Re: How are cyber criminals rolling in 2025?

#76

Earlier quoted context omitted.

Completely unrelated tangent: Jesus Christ Reddit is such a cesspit. Tried tapping that link on mobile, got a screen to view the corresponding post. Tapped it, and I got taken to the App Store. No thanks, force quit the App Store and go back. Now I get a full screen notice on the original Reddit tab saying “didn’t go where you expected? Next time try the long press!” With instructions to not use private browsing and…

> The entirety of redit.com seems to be just a broken honeypot to get you to use the app instead. I just can’t fathom how a company can be that broken. It's their intention to have the website be a funnel so that they can get more mobile users. I sometimes use https://old.reddit.com , though it doesn't look that great on mobile, maybe there are some other alternatives.

I still don't understand why mobile users are so much more valuable to them, is it just the inability to block ads?

Re: How are cyber criminals rolling in 2025?

#77

Is it just me or is cybersecurity... Calming down? I feel like a few years ago there was constant news of ransomware, intrusions, vulnerabilities, etc, but more recently the defensive side seems to have the upper hand.

There's a lot of other stuff in the news.

Re: How are cyber criminals rolling in 2025?

#78

Among the common vulnerabilities listed: > Outdated Wordpress plugins and CMS systems No surprise, having worked in edu the following scenario was very common: 1) Researcher gets a grant for a project 2) Grad student sets up a Drupal site for the project 3) Things are maintained and updated for a couple of years 4) Grant runs out, project wraps up, student graduates, everyone forgets about the server which sits unatt…

At my old university ~15 years ago, all IPs of all computers were public IPV4 addresses . Any computer plugged in to any ethernet port on campus was given such a "quasi-static" IP address. All normal ports were open - ssh, http(s), you name it. It was the OG zero trust architecture.

I loved that era and it was hugely educational to me, but I can understand why it had to end.

Re: How are cyber criminals rolling in 2025?

#79
post #76

Earlier quoted context omitted.

> The entirety of redit.com seems to be just a broken honeypot to get you to use the app instead. I just can’t fathom how a company can be that broken. It's their intention to have the website be a funnel so that they can get more mobile users. I sometimes use https://old.reddit.com , though it doesn't look that great on mobile, maybe there are some other alternatives.

I still don't understand why mobile users are so much more valuable to them, is it just the inability to block ads?

>is it just the inability to block ads?

Of course it is.

Re: How are cyber criminals rolling in 2025?

#80
post #76

Earlier quoted context omitted.

> The entirety of redit.com seems to be just a broken honeypot to get you to use the app instead. I just can’t fathom how a company can be that broken. It's their intention to have the website be a funnel so that they can get more mobile users. I sometimes use https://old.reddit.com , though it doesn't look that great on mobile, maybe there are some other alternatives.

I still don't understand why mobile users are so much more valuable to them, is it just the inability to block ads?

I know reddit will connect accounts together based on device ID, i wonder if their data becomes more valuable if you can tie multiple independent accounts together in to one profile?

Its a site where users will often have multiple login for different subjects of discussion.

Post reply on HN