2 ms·
A scary reminder of how we're only at the very tip of the social engineering / identity faking problem. An incredible amount of our systems are just based on an
by wild_preference 8y ago
A scary reminder of how we're only at the very tip of the social engineering / identity faking problem. An incredible amount of our systems are just based on an honor system, yet targeted attacks are so, well, targeted that these systems are slow to change.
Like how I reset my Bank of America 2FA three years ago with just my name and billing address of my card.
It's kind of like internet abuse and DDoS in a way: I see HNers recommending something like CloudFront. Yet after being on the receiving end of a dedicated attacker that was able to bleed my financials, I would never use it again. And since it's not a widespread problem by nature of being a targeted attack, people continually have to learn the hard way on an individual basis, if they even get unlucky to begin with. So there's no real widespread need to change.
Or, how many HNers unknowingly use a webhost that null routes them under attack yet never experienced that?