6 ms·
>3. Turn off your computer and personal devices when they’re not in use. This article reads like an AOL scare from 1995 directed at my grandma.
by _eht 10y ago
>3. Turn off your computer and personal devices when they’re not in use.
This article reads like an AOL scare from 1995 directed at my grandma.
- brianmartinek 10y agoAgree. No mention of turning on 2FA as a security measure or using a password manager to help create those "total nonsense" passwords.
- blowski 10y agoAnd yet many people who were born in 1995 are still using crappy passwords, downloading crappy files from crappy sites with no protection. This stuff may be obvious to us, but it seems we're in a minority.
- et-al 10y agoEDIT: If you're going to downvote me, did you even read the article? Also, go look at the submitter's history: https://news.ycombinator.com/submitted?id=vezycash https://news.ycombinator.com/submitted?id=vezycash - - - But should it be on the front page of Hacker News? Why did vezycash take the effort to share this when it has little value for the HN audience? The author nevers explain how their domain was stolen, nor do they tell us if the "sting" operation (asking to stop a wire transfer, hardly a sting) was successful. It's a long-winded rant about HostMonster and GoDaddy being shitty. We already knew these things. If the article was just focused criticism on GoDaddy or clear advice on web security, I wouldn't be so hash. Whatever educational benefits there were in article are lost with the writing. This has got to be on the front page because of some shilling.
- sverige 10y agoIt's obvious, isn't it? It's here because this is Hacker News and the theft of the website was done by hackers so this is news for our consumption. </sarc> (an HTML5 compliant tag, since </s> has been repurposed)
- et-al 10y agoPretty much. I wonder how many people actually read the article.
- blowski 10y agoI found it an interesting story to share with non-techie people about why they need to worry about security. Also, HN Guidelines ask you not to suggest people haven't read the article. If you don't like the article, flag it or make a constructive comment (which I think you did) and move on.
- et-al 10y agoCheers, thanks.
- bittercynic 10y agoI think it is valuable to be reminded of the depth of ignorance of even "tech savvy" people.
- et-al 10y agoThe author is a lifestyle blogger, not a tech savvy person.
- bittercynic 10y agoSince she owns and operates a blog, an average person would consider her highly tech savvy.
- tdb7893 10y agoI think the mere fact that they leveraged her email to steal her domain is interesting. You generally don't think of a domain as something people steal
- tedunangst 10y agoNo? There have been any number of high profile domain hijacks. sex.com being pretty infamous.
- et-al 10y agoLeveraging an email to steal anything is nothing new. If this is arguably a revelation, I should start asking this as an interview question. Also, the author never explicitly mentions to secure your email address. In the 2000s, domain hijackings were very common (as tedunangst mentioned): http://www.metafilter.com/3789/Adobecom-gets-hijacked http://www.metafilter.com/3789/Adobecom-gets-hijacked http://archive.wired.com/politics/law/news/2000/04/35674?currentPage=all http://archive.wired.com/politics/law/news/2000/04/35674?cur... Later on, it became short Twitter accounts: https://medium.com/@N/how-i-lost-my-50-000-twitter-username-24eb09e026dd#.7rf3w1iqi https://medium.com/@N/how-i-lost-my-50-000-twitter-username-... https://www.wired.com/2016/06/deray-twitter-hack-2-factor-isnt-enough/ https://www.wired.com/2016/06/deray-twitter-hack-2-factor-is... If your metric is how informative an article is, the above two links about Twitter accounts being hijacked are much more educational than original blogpost.
- mustacheemperor 10y agoThe link to a Traveler's Insurance page with advice to purchase cyber risk insurance (delivered with the same gravity as the advice about changing your passwords) definitely made me ask the same questions. I thought the next line was going to be about X product the author is selling that would prevent this problem for you.
- mirimir 10y agoMore like sympathy, I think.
- Ajedi32 10y ago> EDIT: If you're going to downvote me, did you even read the article? I think the downvotes are because you're accusing the submitter and the people upvoting this article of shilling based on nothing but circumstantial evidence, not because of your opinion on the quality of the linked article.
- et-al 10y agoFair point on the upvoters, but I still stand by my point on the submitter. Who has the time to submit an article to HN every day?
- CM30 10y agoQuite a lot of people? I mean, I don't myself (because I don't come across enough articles I feel people here wuld be interested in), but it wouldn't be too much of a hassle if I did. People have time to constantly use Twitter/Facebook/YouTube/Reddit/Tumblr/internet forums in general, they can easily post an article on Hacker News once a day.
- Ajedi32 10y agoI think the point is that "Turn off your computer and personal devices when they’re not in use." is not an effective security measure. (What are you worried about? Malware? Malware can steal your account just as easily when you _are_ using your computer as when you aren't.) Some of the other advice in that section is also rather questionable. (E.g. "Your password should not contain “real” words".)
- discreditable 10y ago> 3. Turn off your computer and personal devices when they’re not in use. Even Bruce Schneier recommends you do that[1]. The idea is that if your machine is a spambot and you don't know it, there are fewer windows of time where your machine can be blasting the Internet with spam. Or if there's some network-based exploit, you're not vulnerable while your device is off. 1. https://www.schneier.com/blog/archives/2004/12/safe_personal_c.html https://www.schneier.com/blog/archives/2004/12/safe_personal...
- Ajedi32 10y ago> Turn off the computer when you're not using it, especially if you have an "always on" Internet connection. How old is that article? Sounds like this is from the days back when dial-up was still popular. I guess there may be some marginal increase in security by turning off your computer like this, but I don't think it's the kind of thing most users should be worried about. > if your machine is a spambot and you don't know it, there are fewer windows of time where your machine can be blasting the Internet with spam If your machine is part of a botnet, you're already compromised and turning it off when you're not using it isn't going to fix that. It might marginally help _other_ people getting DDoSed or spammed by your PC, but it won't improve your own security. > Or if there's some network-based exploit, you're not vulnerable while your device is off I guess. But unless you become aware of the exploit and take measures to mitigate it before turning your PC on and connecting it to the internet, leaving it off when you're not using it is unlikely to help with this - you'll just be compromised as soon as you turn your PC on. Not to mention that the kind of zero-day that would allow compromising a fully up-to-date PC with nothing more than network access to it is extremely rare. I'd argue the security benefits of leaving your computer on so it can auto-install security updates while you're away probably outweighs any marginal benefits you might get from turning it off when not using it. (Though either way the difference is extremely minor.)
- discreditable 10y agoThe article is from 2004. Keep in mind it's geared towards being very simple. I don't think some of the advice is good, such as deleting cmd.exe and command.com.