Live data from Hacker News

The fake browser update scam gets a makeover

krebsonsecurity.com

91–100 of 196 posts

Re: The fake browser update scam gets a makeover

#91

Earlier quoted context omitted.

Doesn't TorBroswer also deserve more criticism by that logic? Here is their reply to this: https://support.torproject.org/abuse/

People abandon all analysis when it comes to Tor. Yes, Tor serves a legitimate purpose (in contrast to Monero, noone has changed my mind yet), but I'd argue that value would also be fullfilled without onion services. If I have to gess 99 % of onion services are illegal activity. The only exception to this rule is SecureDrop which I am certain could be realized with just a regular server too. You need to self host it…

I use Monero to donate to FLOSS software projects and as a way of paying friends without surveillance capitalism demanding I tell them what my private transactions are for. If these aren't "legitimate purposes" then there no point in engaging in this conversation. Maybe you're happy with being subject to corporate panopticons of Venmo/Cash App/whatever but I'd rather not engage with companies that seek to demand an ever larger pool of information from me.

Onion services provide authentication and NAT traversal while maintaining security and anonymity. Just because you aren't using that functionality doesn't mean it doesn't have a use.

How do you intend to have a clearnet application that can stand up to the same threat model that SecureDrop does?

Re: The fake browser update scam gets a makeover

#92
post #84
post #80

Earlier quoted context omitted.

seems like "blockchain" has nothing to do with it... they could just host the file on a server they do control. "Blockchains" aren't magic.

It's not magic but it is a radically different pricing model: pay once, host forever. I see it as a massive bet on storage prices continuing to decrease.

If it becomes a problem consensus can evolve to trim inactive data (say expiring unspent outputs after N blocks in UTXO chains, "move it or lose it" model) or explicit charging for storage per unit of size and time (decay some associated balance accordingly).

Re: The fake browser update scam gets a makeover

#93
post #2

The quality of full screen takeover pages seems to have dramatically risen recently. My family members, who don’t know the Escape key exists, accidentally click one from a banner ad every week now taking them to a page like examplefoobar38561.cloudfront.net and the use of elements that imitate browser or OS chrome (generally imitating Windows Defender or similar) has reached near perfection. All browsers should have…

After seeing Krebs' post the other day, we now have a call scheduled with my partner's parents who still own a Windows laptop.

I'm going to tell them that they should no longer use it for any sort of financial work. No banks, no shares, nothing. Ever, for any reason.

This stuff is too good now. Most of us -- and I include the tech-literate, because we all slip eventually -- are basically helpless at this point.

Solution? iOS apps, or, I'm sorry, use a Mac. I know it's not immune to malware but for all practical purposes it might as well be.

Re: The fake browser update scam gets a makeover

#94
post #4

Seriously considering running a JIT-less JavaScript free browser should be the standard for surfing these days, and only whitelisting sites you trust (like your online banking site or Amazon for example). Disabling JS wipes out entire classes of attacks. I know developers assume the user has JS enabled and codes their site to that end, but a small minority disables JS to get rid of various annoyances and for accessib…

I would argue that a world that didn't have JS would make these types of attacks more common, not less common. Because in that world, people would have to download desktop apps for everything, which would make people used to downloading desktop apps from random Web pages, which would make malware easier to distribute. In fact, we don't have to imagine that world: it was the world of the late 90s.

In an ideal world, native apps shouldn't be able to compromise your whole system.

Re: The fake browser update scam gets a makeover

#95
post #82
post #78

Earlier quoted context omitted.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

Preserving privacy, reliable transactions with no, i repeat, no bank or govmnt involvement, no kyc. No/low fees (on some currencies), public immutable databases...

> Preserving privacy

Literally does not understand crypto.

Re: The fake browser update scam gets a makeover

#96
post #91

Earlier quoted context omitted.

People abandon all analysis when it comes to Tor. Yes, Tor serves a legitimate purpose (in contrast to Monero, noone has changed my mind yet), but I'd argue that value would also be fullfilled without onion services. If I have to gess 99 % of onion services are illegal activity. The only exception to this rule is SecureDrop which I am certain could be realized with just a regular server too. You need to self host it…

I use Monero to donate to FLOSS software projects and as a way of paying friends without surveillance capitalism demanding I tell them what my private transactions are for. If these aren't "legitimate purposes" then there no point in engaging in this conversation. Maybe you're happy with being subject to corporate panopticons of Venmo/Cash App/whatever but I'd rather not engage with companies that seek to demand an e…

> Maybe you're happy with being subject to corporate panopticons of Venmo/Cash App/whatever

Get this, I've never used either of these services before. And the even crazier part is that if I did, they wouldn't know what I'm giving my friends money for anyways. And lastly, just use cash if your decision making is being opressed by the surveillance capitalism. Monero serves no purpose that hasn't already been fullfilled by a non-dubious measure

> How do you intend to have a clearnet application that can stand up to the same threat model that SecureDrop does?

I don't know, ask Stripe maybe how they haven't gotten any customer data stolen yet with their massive threat profile while not using Tor in any capacity

Re: The fake browser update scam gets a makeover

#97
post #82
post #78

Earlier quoted context omitted.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

Preserving privacy, reliable transactions with no, i repeat, no bank or govmnt involvement, no kyc. No/low fees (on some currencies), public immutable databases...

Somehow I'm living day to day without needing to think about being associated with a service I am paying for. I totally get your point about minimizing interference, but there is absolutely no way anyone thinks Monero is a good solution to this problem who isn't involved in some shady business.

Re: The fake browser update scam gets a makeover

#98
post #82

Earlier quoted context omitted.

Preserving privacy, reliable transactions with no, i repeat, no bank or govmnt involvement, no kyc. No/low fees (on some currencies), public immutable databases...

> Preserving privacy Literally does not understand crypto.

cough monero cough

Re: The fake browser update scam gets a makeover

#99
post #4

Seriously considering running a JIT-less JavaScript free browser should be the standard for surfing these days, and only whitelisting sites you trust (like your online banking site or Amazon for example). Disabling JS wipes out entire classes of attacks. I know developers assume the user has JS enabled and codes their site to that end, but a small minority disables JS to get rid of various annoyances and for accessib…

Or alternatively, you can pursue security through compartmentalization. My VM for random browsing has JS enabled, but if I'm hacked, the attacker will not get access to any files. Also the VM is destroyed when the browser is closed.

What’s the threat model here? Javascript sandbox escapes are extremely rare these days (subjectively they happen less frequently that image or video codec bugs).

Re: The fake browser update scam gets a makeover

#100

Good ol' Krebs and Schneier ..either way too late to a scam, or ignoring other scams, or ineffectual regardless. What about those fake "download here" Adword buttons that have been a scourge of the web for the past decade or longer infecting untold millions of computers with malware. When will anyone bring that up.

A good takeaway from this is that 1) the simplest methods can stick around the longest. His skimmer page is 13 years old and it's still relevant, for example. Similarly, we will not be rid of fake download buttons or compromised wordpress sites in our lifetimes. 2) If you write about the simple stuff, your articles will be evergreen. You don't have to time the market when your product never falls out of demand.

Google can simply decline to run any ad which has the words "download here" as an image. how hard is that? I guess people do not come forward and less media coverage, unlike crypto losses and scams.
Post reply on HN