Live data from Hacker News

On Getting Hacked

ahmeto.com

1–10 of 77 posts

Re: On Getting Hacked

#2
It is an humbling experience the moment when you accept that getting hacked is something that can happen to anyone, including the best of us. No one is too good not to be hacked.

Re: On Getting Hacked

#4
post #2

It is an humbling experience the moment when you accept that getting hacked is something that can happen to anyone, including the best of us. No one is too good not to be hacked.

I work in payments and yet I once gave my card (and 3DS auth!) to a phisher. Thankfully I realized what had happened pretty quickly and immediately deactivated the card. But the fact that I went through the whole process before realizing was pretty harrowing. For all I know, that might not have been the first time.

Re: On Getting Hacked

#5
> open their password manager which also might need you to authenticate, type in their master password, search for the name of the said website, copy the password, paste it in

This is one way to guarantee you'll eventually fall for a phishing attack. Are we really running URL-unaware password managers in the year 2026?

Re: On Getting Hacked

#6
Not all too long ago I had someone port out my VOIP number. They had it for a few hours. This was after I had spent extensive effort attempting to secure my digital life. VOIP was SIM-swap resistant sure, but I totally missed that port out requests default to failing open.

Thankfully the VOIP operator alerted me and pulled the number back. Then I set a port out code.

Who knows how many other holes I have. I lost my sense of smugness that day.

Re: On Getting Hacked

#7
In the moment, it doesn't feel off, that's the most disconcerting aspect. It's the things that don't seem so critical or important that get you as well. Registration on a random site, and for a temporary reason was what got me once. In this case the browser extension seemed almost like an afterthought at the time for the author.

Re: On Getting Hacked

#8
post #5

> open their password manager which also might need you to authenticate, type in their master password, search for the name of the said website, copy the password, paste it in This is one way to guarantee you'll eventually fall for a phishing attack. Are we really running URL-unaware password managers in the year 2026?

Lots of people are afraid of attacks on the browser extension.

There have been exploits for them in the past, it's a legitimate concern.

Deciding between the two setups is a tradeoff between one security issue and another.

Re: On Getting Hacked

#9
Had a close call:

Apparently it's possible to bypass 2FA and do a password reset of a Google account without email access, if the account owner doesn't abort it within 30 days. I confirmed that it works by "pwning myself" afterwards. So keep an eye on your old Gmail inbox if it matters.

Re: On Getting Hacked

#10
> At this point, I am the old lady who is driving to a Target to buy gift cards and give them to Jared, who is the Amazon Customer Support specialist with a suspiciously heavy Indian accent, waiting on the phone.

It happens to all of us. I always tend to make sure any extension has the sources available (unless requested by work/client), but nowadays with open source supply chain attack, it's just another breakable wall. Even on linux, some long time ago, I caught a trojan (luckily to the extent of my knowledge, it didn't affect anything besides running a crypto mining on my m3 laptop)., disguised as systemd, that was spreading through kodi extensions.

Post reply on HN