73 comments

[ 6.3 ms ] story [ 146 ms ] thread
Summary: Hackers send grandmother phishing mail. Grandmother enter her email address and password. Hackers go into house of Grandmother. Hackers change settings on router and and television of grandmother.
Yeah, this isn't really that scary as long as you know how to spot phishing scams. Am disappoint.
A chain is only as strong as its weakest link. If anyone has enough privileges for a malicious attacker to use their account/info to compromise your network then that is the measure of how well protected you are. In this case it was a grandmother, but it doesn't have to be. It could be a salesperson, an HR manager, a burnt out developer. When a business grows to a sufficient size that there are people working in it who are disinterested in "computers" or "processes" (in the case of a software startup that's probably over about 10 staff), then you suddenly introduce some huge weak points in your IT infrastructure. That should be scary.
Yeah, I guess I should be scared that companies I trust might be making these types of mistakes; I hadn't seen it from that angle.

I'm just disappointed that the article was about "hackers" but just talked about scams most of us are already aware of; seems kind of click-baity. They could have entitled the article "Here's One Easy Trick to Protect Yourself from Identity Theft."

curious, is this really a bot or someone just providing a service under the guise of a bot?

be pretty cool if it was the former. that would be some serious natural language processing. (not that i know anything about that subject)

i read the article, this post does seem like a pretty accurate summary.

Its difficult for one person to judge that. Some kind of bias creeps in when you read the article and see the summary again since your mind fills the gap automatically which is created by the summary.
Yeah, I don't consider the phishing scams interesting at all. This seems like more of a marketing stunt than anything. And it's borderline not hacking.

They actually didn't even do the whole thing themselves. Instead hired a phishing service...

To me this is more similar to people dressed as UPS truck drivers going inside an apartment and stealing keys. Or a cashier taking a picture of a customer's credit card.

P.S. Excellent bot if it is a bot. It seems to be taking sides on an issue and not just summarizing, which I haven't seen happen previously with any other summary bots.

Phishing is hacking. It's social engineering.

They didn't 'hire a phishing service'. They used a website.

Social Engineering is absolutely hacking. This wasn't a sophisticated example, but it's still a very real threat.
I guess I have a narrower definition of hacking, specifically that it is using technology in a way it wasn't intended. If you ask someone for their credentials and they give them to you, I don't see that as being "a hack," although I guess modern parlance would say the victim "was hacked."
"Hacking" is in everyday parlance not too far from "gaining unauthorised access to a technical system."

Social engineering is often a very efficient alternative to rainbow tables, wiretapping, buffer overruns and other technical exploits.

It's often the only or best way too. The more secure a place is the easier it is to get in. People become very trusting. Carry a clipbord and look like you know where you're going and you can walk damn near anywhere.
Years ago a friend's house was burgled. They took blank checks and statements, among other things, and spent her money. It took a long time to unwind that.

Physically breaking in is a real threat. Now break-ins risk digital breaches as well as the old standards. Just because it involves being onsite doesn't mean it isn't a meaningful threat, and now it's not limited to just the artifacts that are stolen.

In fact, "standard" protocol in response to a physical home breakin should probably include a digital "audit."

Well actually, looking at the things my parents and parents in law did on their home networks, their Smart TVs and so on, having this in a understandable form for the lay person is really good.

To understand, that your door opener, your TV and other things can be "hacked" is important. The information to use different passwords for every service is important.

We as people in the know have to help our elders and peers to see how easy it is to use a pwd-mgr and have a little bit more basic security.

If nothing more, this piece goes a step in the right direction.

Don't trust password managers. They are hackable pieces of software just like the ones you are trying to protect. And they are not reliable (see last news of Lastpass acquisition by LogMeIn).

I'm not saying you should ditch password managers and just memorize all of your password. I'm just saying: use them as a well-informed user.

Back in the days, Bruce Schneier suggested to write passwords down on a piece of paper and keep it in your wallet as the least weak security measure. Today, based on this article[0], he actually recommends the use of a password manager "[...] simply because it allows you to choose longer and stronger passwords.", which basically means it's the lesser of two evils.

[0] https://www.schneier.com/blog/archives/2014/09/security_of_p...

Not all password managers are commercial, closed-source, and cloud-connected. This probably wasn't a main point of yours, but since you mentioned LastPass I felt this should be clarified.

I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser.

I've been thinking about converting an old Android device into a more secure password manager. I envision having the device hold the decryption key for the PW "vault" as long as it's connected to my authenticated system. I either request credentials from the PC and approve on-device, or select them on the screen, and it types them as a USB keyboard (or perhaps some other way less prone to garden-variety keyloggers.) I guess I haven't because it's kind of a lot of effort and will lower convenience levels. :)

I ought to at least find a better way than the clipboard, to transfer passwords from the manager app to the browser etc...

I want a small hardware, non-connected tablet that acts exclusively as a password manager. It connects to the computer I'm using as a USB keyboard device and only "types" a password when I physically tell it to ("yubikey on steroids"). Backups and system updates via flash card with encrypted filesystem. No wifi, no bluetooth, no phone, no ethernet, no other purpose.

Edit: heh, that's funny, you edited your comment as I was replying? Now we just need someone to build it for us :)

Haha, I also thought your comment was a response to what I edited-in about my hardware idea, but yes, we must have been writing it at the same time.

When Bitcoin hardware wallets were first getting developed, I wondered why people didn't just start with open, barebones commodity hardware like you've described. Well, I suppose one reason may be that it may not exist, but it seems like it should be pretty cheap to pay some low-end Android manufacturer to remove a few features from their design. Or maybe you even buy "normal" hardware and strip out radios. At some level, the wallet manufacturers are all trusting someone, as I don't think any have designed their own low-level components. Anyway, maybe I will revisit that idea to see if a suitable locked-down, easy-to-hack, super-cheap device is available, as I agree that cutting all unnecessary comms is a good idea.

For radio-free hardware, what about a Palm Pilot? Only has IrDA.
A couple of them had Bluetooth. The only 68k-based one with builtin Wi-Fi was the AlphaSmart Dana, a writer's keyboard.

You're very very unlikely going to want to type a truly secure (= long) password over and over and over, which you'd need to do in a situation where the browser's password manager is turned off, and/or a website disables password caching anyway.

The Palm m5xx series could solve this problem: it had full USB, and I once read of an Palm app (like any other) that bridged the m5xx's SD slot to behave like a block device over USB, ie it turned the Palm into a USB SD card reader. That means there's a raw USB SDK out there, and adding HID keyboard support wouldn't be too hard (no kernel driver development etc).

Getting passwords into the device would be nontrivial; Palm keyboards are proprietary to the series they were made for, with a few arbitrary connector updates thrown in for good measure (think iPhone docking connector saga). If the password is irritating enough to repeatedly type on a full keyboard, it would take you a good 5 minutes (and a punching bag, for afterwards) to get it into the PDA, Graffiti and custom keyboards taken into account.

I think it would work out though: if the only way to get data out of the device is to tap something on its screen, that should be enough of a brick wall to dissuade would-be attackers.

I guess I'm responding to this so enthusiastically because it's about Palm :P - I unfortunately never owned one of these awesome little things, but I'd love something of similar capabilities built using today's tech. With modern advances in power consumption, like MemoryLCD, micropower CPUs, short-range bluetooth, etc, the result would probably last literally weeks. It'd be enormous fun to hack on, too, and carve out a little niche for itself. :)

I wonder if I should Ask HN if this would be a good idea.

> I wonder if I should Ask HN if this would be a good idea.

  3. Ask HN ask HN: Should I ask HN if a Palm Pilot keyboard would be a good password manager?
  1 point by i336_ 1 minute ago | flag | past | web | discuss
Point taken; that was the wrong way to say it :P

Also, to clarify - and I should've qualified what I meant, but tiredness is such an unhelpful thing at times - this is a genuinely interesting-sounding idea (as I noted to the other reply at this comment depth), but the paragraph at the bottom was kind of an independent thing.

I've always wanted to tinker around with a handheld, reasonably nice-looking device with similar specs to a Palm. Sort of like the TI watch (http://processors.wiki.ti.com/index.php/EZ430-Chronos), but a PDA equivalent.

Just make something like a usb Rubber Ducky with a couple buttons and a screen. Plug it in, scroll to password, hit "type it", and it types it in. Could probably make one for about $40. Arduino Leonardo, LCD Shield, and the leonardo keyboard libraries. Could even have it as a full password generator too.
That actually sounds like a really, really good idea.

Although... I just started thinking about the possibility of using a microcontroller that had a tiny bit of internal, non-reprogrammable ROM, so I could implement a secure stage-0 loader... lol

meh, that seems like a protection against physical access, if all else is done correctly, and you are screwed at that point.

In other news, I just placed an order for the parts for my prototype, so I'll be putting that together this weekend. Fun thing: If done correctly, it should work with most android phones, as they do understand usb hid keyboards. As a result, final design may end up with a very small lithium battery to allow it to run when connected to a phone that doesn't offer much power. I'll put a blog somewhere and post an update to https://twitter.com/andy_leap as I work on it.

how about this, as an alternative to going down the route of secure loaders and such.

The firmware that's written to the chip is padded out to (sizeof(flash)-X) with cryptographicly secure random bytes, where X is the size of a crypto signature block, which you use to sign the firmware. When you plug the thing into a computer without the sd card inserted(I plan on storing the password vault on an sd card, correctly encrypted), it dumps all of the flash via keyboard. Pipe that into a program that verifies the signature, via whatever means, and you can ensure the firmware has not been tampered short of hardware modification in the form of adding more flash memory/eeprom, as to do so would require compressing the existing code/cryptgraphically secure padding, as you would need to dump the original out to pass the verification. If you want to be even more secure, you can even replace the existing signature with your own, therefore ensuring that people can't change the version without access to your private key.

I had and enjoyed an m515. :) I see there are several for less than $30 on eBay. Maybe that wouldn't last if someone built the software and a bunch of paranoid power-users started buying them. :P The potential to recycle some old hardware is part of what makes this idea interesting to me.

I suppose if you can do full USB, you can probably get data in somehow.

Cool, thanks! It's funny that I and other potential target audience members here, were apparently unaware of this; the internet is a big place. It's a bit too expensive for me, I think -- at least the pre-assembled version. I may steal the smartcard idea, though (or some other form of hardware security.) It might be possible to coerce a phone's SIM slot into serving as an interface to a card.
Hey, I'd be willing to build such a thing. Open source hardware and software and all. Email me at kliment@0xfb.com
heh, I'm interested too, what kinda hardware would you use?
"I ought to at least find a better way than the clipboard, to transfer passwords from the manager app to the browser etc..."

With X selection buffers, when you're pasting data the X application you're pasting from gets to run arbitrary code (informed of the destination!) to determine what to send. I've been wanting a password manager that asks me for verification before transferring the data.

Don't forget that your clipboard manager also stores the last N things you copied in your clipboard history. I won't lie, it is very convenient for passwords I need to type frequently while sitting on a machine I trust, that doesn't run any remote logging applications and that locks when I'm not there, but it's still obviously a security issue.
A clipboard manager, if you have one, is a separate X application. The password manager could deny it access, if that's what you'd prefer.
Keepass, at least, clears the password from the clipboard with a short timeout (default is 10s or so).
heh, I could build a prototype for $40~$50 or so, maybe we need to start a kickstarter
KeePass is also an offline option. It includes the ability for auto type to split data among the clipboard and keyboard. Though I didn't like how wide open it is when unlocked, so I made LockyWindow as an plugin to fix that.
(comment deleted)
If someone has access to your local passwordmanager he can also keylog everything you type in. Okay, if he can hack your passwordmanager he gets all of your passwords at the same time. Thats a point.

It matters with one goes faster: Cranking your PW manager or you typing in all your passwords.

It's easy to dismiss it as a phishing scam but these days some of them can be very convincing and elaborate. It's not hard to obscure URLs, obtain good looking SSL certs, and have a good story behind it. Social engineering will always work.
"Critical points were that Mrs. Walsh needed a new garage door opener..."

I'm surprised they only care about the electronic locks and didn't show how easy it is to pick most of the mechanical locks. Especially when they are talking about the "not hyperconnected" hacks.

Or, you know, break the window, if the garage has a window, or use some other more brute force technique. Less stealthy, but not incredibly different for most purposes.
And with just a roll of duct tape you can silently break a window.
Fake virus warnings also sucker a lot of older people. Putting them on Chromebooks kills a lot of birds with one stone.
>> To spare Mrs. Walsh any actual harm, the hackers used a service called Phish5, which does not actually store passwords and is often used by employers to test employees’ ability to spot malicious phishing cons.

I'm signing up for Phish5. Looks like exactly what I need for my team.

Hackers can "pwn" you by not even hacking you. If someone can hack e.g. your phone provider or something you can get even worse problems and you did not anything wrong.
This is more about how hackers use phishing (old) to get passwords etc. Nothing new. Actually looks like phishing works best on those not hyperconnected or heavy internent users because they would most likely know the pitfalls.
This is a silly article with an alarmist title. They look at a list of sites she likes on Facebook, then they phish her from one of them. Then she lets them into her house where they look for post-it notes with passwords on them. For a grand finale, they open her garage door. I guess the takeaway here is don't let people that identify themselves as "hackers" through your door and into your home office if you have passwords written on post-its, but I am fairly certain this is a rare occurrence.
The title isn't alarmist. The victim was an ordinary who didn't have a particularly "IoT" home and wasn't a heavy Internet user. They were hacked successfully.

It is a useful article as a warning for non-technical people.

To be honest I don't think technical people are above this either... either as civilians or as service designers
I think it kind of is. There wasn't really hacking involved here, just people taking advantage of an older woman and "pwning" her. Really cringey if you ask me.
This was the day when you learned how a huge portion of serious "hacking" is done. Taking advantage of the right older women is a very time efficient way of gaining access to systems you shouldn't have access to.

If you want to know more, I can recommend The Art of Deception by Kevin Mitnick.

Social engineering and brute force attacks aren't "hacking"? Come on.
Criminals who commit identity theft don't care what you find cringey. She (and people like her) are vulnerable, and that's a fact worth knowing.
(comment deleted)
I'd disagree, I think is an excellent example of people who think they don't need to worry about security because they aren't on the Internet very much. It was all pretty mundane I agree, right up until they had her power of attorney and social security number.

This should be a wake up call to the have-nots: You aren't safe just because you don't post on Facebook and you don't use the computer. Just because you don't drive doesn't mean you can't be hit by a car.

>It was all pretty mundane I agree, right up until they had her power of attorney and social security number.

They only got these after she let them into her house and gave them physical access to her computer. Of course it's only common sense that anyone that is allowed into your home and onto your computer can "pwn" you and worse - hacker or not. That's why 99.9% of people, including this woman, wouldn't allow strangers into their home and give them unfettered physical access to their computer.

The article title implies that they were able to "pwn" her through "hacking". The only mildly interesting they did in this regard was the spear-phishing attack based on her Facebook likes.

As I read it, they got that information from her email, and were I a betting man I'd say probably Yahoo or Gmail. They already had her password; getting it from the website would be trivial. This is all my own assumption of course.

The underscore here is that a limited use case person, someone who occasionally posts limited things and doesn't do anything beyond casual ebaying can still be a victim.

Yes, they got it from email, but they didn't get into the email until they were in the house and got the password from a post-it note for the main account, and the daughter had the browser auto-fill it. They wouldn't have had either of these without a willing participant that let them into the house to find the information. It's like saying "I was easily able to rob the bank vault after the manager opened it".
You make it sound like achieving remote access to this machine with two dozen malicious programs on it would be difficult. I highly doubt the machine is as hardened as her Facebook is.

The chain is only as strong as it's weakest link.

That is a false equivalence though. There is no phenomenon of hackers breaking into people's homes via garage doors openers in hopes to find passwords written on post-it notes. If I break into your home, I'm not looking for post-it notes. I'm looking for small yet valuable objects that are easily pawned.

If I have a vendata against you, I can break into your home and setup keyloggers, hidden video/audio recorders that "call home" or even allow me to "dial in" and listen in. I don't need your stinking post-it notes and I won't even have to be in a rush. (http://www.amazon.com/dp/B00CIXAF8O/ref=wl_it_dp_o_pC_S_ttl?...)

The only thing this pawnage verified for me is that there are a lot of people with malware running on their computers and these same people are susceptible to phishing scams.

>she lets them into her house

She didn't need to though, they could have entered through the garage door while she was away.

So many people here are dismissing this as unsophisticated.

Burglars have always targeted items that are valuable to them. Easy to sell, gets a good price, etc.

Now we have digital assets in the home, and burglars are going to focus on those things too. For most of the population, and probably many of "us", physical access to those digital assets isn't particularly secure. And to have those assets "taken" today is much more far reaching than to have lost a stereo or checkbook.

Just because the attacker had to get off his couch and go somewhere shouldn't minimize this threat. "Physical access means's you're pwned" is a true statement.

One thing I do at home, for example, is to use full disk encryption on my laptop, and hibernate it when I leave. So that if someone steals it, it's just a plastic brick. For exactly the scenario described in the article.

I have always considered it to be a good practice to use disk encryption on laptops (or other mobile devices), but after thinking about the burglar scenario, I think it is better to encrypt the desktops as well.
yeah you can break into anyone's homes without a computer, imagine that media!
So "those not hyperconnected" means just normal people?

I don't claim to be hacking proof since I don't control every bit of my data myself, but if someone came into my house they wouldn't find passwords in a notebook or saved passwords in my browsers

Aren't they crackers instead of hackers?
An interesting piece and definitely has some merit depending on the audience. False sense of security. Bad habits. This is kind of an exaggerated approach to teaching.

For anybody who doubts that "gaining physical access" automatically disqualifies the results, let me share a recent uptick in a specific con in my area that could very well be adapted as a template to other unsuspecting areas:

Two men in hard-hats and workman clothes approach a home, clipboard in hand, and claim to be with the "power company" and want to have a moment of time to talk about some trees close to the power lines. It's a right of way issue. They ask for the resident to come out and take a look with them. All seems pretty normal.

The talker gets the person or couple's attention while the other makes a quick excuse to go back to the truck out in front of the house. The talker carries on about how they're going to take care of the trees at no cost to the residents, and they act very cordial overall. Meanwhile, the partner has gone into the home via the front door which was left unlocked, goes for the most likely targets of value (ex: jewelry). The partner goes to the truck while talker wraps up and leaves. By the time the residents notice anything is amiss, the duo are long gone.

Trust-cons are a huge issue for a large portion of the population, in my opinion. Being prepared to be charmed while being fleeced is not how normal people go about their day.