Live data from Hacker News

I was seven words away from being spear-phished

robertheaton.com

91–100 of 187 posts

Re: I was seven words away from being spear-phished

#91
post #56
post #6

It's always nice to get a good healthy dose of paranoia in the morning. This makes me think back to how my sec professor had a separate system that he'd use to access his online banking.

I use a dedicated VM. It is only started when I need to do some banking, and can't talk to most of the internet.

I don't get it, shouldn't you use the VM for accessing everything except your bank?

If the host gets compromised from non-banking activity, it can just take over your VM.

Re: I was seven words away from being spear-phished

#92

The specifics of this - the request to judge a prize one is clearly unqualified for - are we as software engineers particularly vulnerable to? Most people would, I think, conclude "this is fake, because why would I be asked to do this?". But I often think that as software engineers we fancy ourselves to have more insight into other fields than we really do. Does this ring true to anyone else?

Ah, but can you be sure you're unqualified to judge a prize you haven't heard of without first visiting their website and figuring out what the prize is about?

Maybe the Adam Smith prize has a category for best embedded linux build system, or best strong beer...

Re: I was seven words away from being spear-phished

#93
post #74

I think the real moral of this story is that (like the fun vulnerabilities on Flash and Java that we might remember), a combination of keylogger or strange daemon might be running suddendly on your machine, scanning your files, either on OSX or Windows. Simply visiting a website. So better (as said) is to use a separate VM to access trusted domains (and yes, also VMs aren't these days so trustable). Better to use 2FA…

So better (as said) is to use a separate VM to access trusted domains (and yes, also VMs aren't these days so trustable).

I would use the VM for accessing untrusted domains. If an exploit has your host system, then it also has the trusted VM.

ciphering on-disk sensitive info

If an exploit has root-kitted your system, encryption does not help much. Presumably you have the unencrypted volume mounted, moreover, the attacker could log keystrokes.

If your machine is compromized, it is basically game over. Change all your bank accounts, e-mail, etc. credentials immediately, wipe the disk. By suspicious about any file the malware may have touched.

Re: I was seven words away from being spear-phished

#94
post #48

Earlier quoted context omitted.

I once read a theory that poor grammar, particularly with 419 scams, acts as a sort of gullibility filter where only the most susceptible targets will respond.

I doubt it in this case. It sounds like they had a browser zero-day, and could potentially steal cryptocurrencies from people they were targeting. You don't particularly care how gullible someone is; if you get your zero-day to successfully work on them and steal all their Bitcoin, there's nothing they can do about it. I think the default assumption is the correct one here; the attacker(s) are a solo or small group o…

You may be overestimating the writing ability of native English speakers.

Re: I was seven words away from being spear-phished

#95
post #48

This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn'…

I once read a theory that poor grammar, particularly with 419 scams, acts as a sort of gullibility filter where only the most susceptible targets will respond.

When you're trying to trick people into sending money orders over seas that makes sense but not really when you're trying to get people to click a link that exploits a zero day to install malware.

Re: I was seven words away from being spear-phished

#96
post #60

Earlier quoted context omitted.

Chrome had a nasty one back in March, so your presumption seems correct. Really, the best way to protect yourself is to use an obscure OS, or a separate machine for web browsing. Sounds paranoid, but the web is THE main attack vector these days.

There are disadvantages to using an obscure OS too, in that it is likely slower to get security fixes, and may have more security flaws.

You could use something like NixOS, which has interpreters, libc, etc. in non-canonical paths. And you still have the protections of Linux and speedy security updates.

Of course, this is security by obscurity, an attacker could adjust the malware for such cases.

Re: I was seven words away from being spear-phished

#97

The two questions that immediately jumped to my mind on this are 1) does Coinbase's user base skew more towards Firefox than the average, possibly because of perceived better security/privacy and a desire for that among cryptocurrency users? 2) did the zeroday impact Tor browser users, and does Coinbase have a lot of those?

I don't think Coinbase users are looking for security/privacy. To be specific, Coinbase is considered a novice cryptocurrency user platform since they have some relatively hefty fees in exchange for being simple to use AKA "It's for normies".

Re: I was seven words away from being spear-phished

#98
post #35

Earlier quoted context omitted.

A few days ago, I also received the same message from a friend with a link to a fake youtube page, but unlike you, I actually clicked it despite intuitively knowing that it was malicious. Seemed like a "regular" phishing attempt but I now wonder if it is more than that, having read this article.

Probably not a good idea to click a link you know is malicious, you never know what 0-Day they might have

That's what I keep my old Blackberry Z10 for. If I get something weird or want to go to dangerous places on internet (for research obviously) I use that thing. I'm pretty sure know one writes a 0-day for a 0.0% market share device.

Re: I was seven words away from being spear-phished

#99
post #55

Earlier quoted context omitted.

Cane here to say the same thing, e.g. https://en.m.wikipedia.org/wiki/Inverkeithing_High_School Although, there's a subtle difference vs US usage: in Scotland High School is only used in the context of the name of a specific school, not as a term for the generic concept. E.g. "What secondary school did you attend?"; "I went to The High School" (meaning the Royal High School in Edinburgh). You'd never say "What high s…

Even that point varies regionally. Where I grew up, in Glasgow, it's really common to talk about primary school kids going off to high school or talk about which high school you attended.

Agreed. I'm in my 50's and even back in the late 70's in Scotland you'd hear folks use "secondary school" and "high school" interchangeably. I myself went to a Scottish "High School" for my secondary education in the 70's/80's.

Re: I was seven words away from being spear-phished

#100

> Looking back it’s obviously completely absurd that the University of Cambridge would ask me to judge an economics competition I don't think this really matters all that much. I might click the link anyway to find out what it is, or to find out why I am allegedly being considered, or even just out of general curiosity. It doesn't _stop_ the attack from working.

I think a process like with unwarranted phone calls is in order. Take the name and contact info provided but Google for the information yourself and contact the official site/email/phone number for information.
Post reply on HN