30 ms·
I was seven words away from being spear-phished
- DangerousPie 7y agoI don't understand the point of using compromised Cambridge accounts for this. All they wanted people to do was to just click on a link. They could have easily registered some legitimate sounding domain name and linked to that instead. It wouldn't be unusual at all for an academic organisation to have a separate site.
- edent 7y agoIt is a prestigious domain - with a high recognition factor. And, as part of that, it will almost never be blocked by URL / DNS filters. In this case, it clearly worked. The user saw cam.ac.uk and trusted it.
- adam12 7y agoI wonder if the attackers were also thinking that these users would more likely be using macOS. The exploit they were using only works in Firefox on macOS.
- karlp 7y agoA compromised Cambridge url gives a lot of credence to their claim though, especially with the paranoid coinbase developer they were targeting.
- bin0 7y agoIt also means the e-mail is significantly more likely to make it past a spam filter, even an aggressive one. There was very little in that e-mail any reasonable spam filter could possibly have flagged, unless they're going to start doing API calls to grammarly. But if they check spelling and grammar, filters will start flagging a lot more than spam.
- gdfasfklshg4 7y ago.ac.uk emails get spam filtered pretty harshly.
- gruez 7y agoreally? why?
- gdfasfklshg4 7y agoNot sure but some guesses: Traditionally students got a lot of leeway with running their own stuff maybe there have been a few doing not-good-things? Lots of academics who don't take security seriously have had more admin access to live servers than they should and then stuff like the article happens?
- lb1lf 7y agoMy Alma Mater, The Norwegian University of Technology and Science in Trondheim, Norway had issues with student E-mails being spamhammered all over the world. Why? All student accounts were hosted under stud.ntnu.no; presumably authors of spam filters made other associations when they saw the string 'stud' than it being short for 'student'. Cough. Their practice of automagically generating user names based on parts of your first and last name in my time led to two users having (for a short time!) the addresses hung@stud.ntnu.no and pervo@stud.ntnu.no.
- fencepost 7y agoTheir practice of automagically generating user names based on parts of your first and last name in my time led to two users having (for a short time!) the addresses hung@stud.ntnu.no and pervo@stud.ntnu.no. Brenda Utthead feels their pain.
- itronitron 7y agoIt's the cyber-version of speaking with a British accent.
- stordoff 7y ago_Any_ other domain, and I'm just going to ignore it. A legitimate *.ac.uk domain, and there's a good chance I will click it to find out what it is, even if I don't believe it. At that point, they've won (it's a 0-day). Using a recognisable domain lets my guard down just enough ("there's no risk in going to a cam.ac.uk domain") for an attack like this to work.
- kache_ 7y agoIt's always nice to get a good healthy dose of paranoia in the morning. This makes me think back to how my sec professor had a separate system that he'd use to access his online banking.
- Topgamer7 7y agoWhat kind of system?
- kache_ 7y agoA linux toaster
- daveslash 7y agoIt toasted linux!? (I'm okay being downvoted a little for that...)
- sansnomme 7y agoElaborate?
- na85 7y ago"toaster" is pretty common argot for "low-power computer"
- jermaustin1 7y agothat seems kind of oxy-moronic? aren't toasters horribly energy hungry?
- wongarsu 7y agoI would have defined toaster as "slow, horribly outdated computer". That also fits your toaster comparison since old computers are very energy hungry compared to similarly speced modern computers.
- luckylion 7y agoIs it still spear-phishing when it's not a phishing attack but an 0day? Is there a better term?
- gruez 7y agoAFAIK spear phishing refers to the fact that the attack is tailored/targeted, rather than mass mailings.
- fwip 7y agoIt doesn't really seem that targeted, just tailored. If they'd only emailed people who used crypto, that might be spear phishing. Edit: nevermind, I didn't realize he worked on coinbase.
- shawabawa3 7y agoThe "spear" means it's targeted, but it's still "phishing" - meaning the attack vector is a cloned version of a legit page I guess this should be called spear-hacking?
- PeterisP 7y agoThis seems to fit the classic definition of spearphishing; the atack vector is an impersonated/fake version of a legit email and its sender. No matter if the payload is in the form of an attachment or web link or a request for some physical action (e.g. please scan and send a copy of your ID) that would fit the phishing title.
- Finnucane 7y agoIt's not clear from the article, since the author didn't (apparently) get successfully targeted, what the ultimate goal of the attack was or whether they were actually after something from a particular individual. However, it doesn't seem like a well-planned attack if that was the case.
- Spare_account 7y agoSome kind of targeted honeypot perhaps? But that is inverted from its typical use. Edit: Maybe a trojan honeypot but I'm literally just stringing words together here.
- aziraphale 7y ago> Neil describes his pre-university education as “High School”. We don’t have “High School” in the UK - we call it “Secondary School”. This might make sense if Neil was American, or trying to communicate with an American audience, but there’s no indication that this is the case. Many secondary schools in the UK still have "High School" in their name. I've always used the two terms interchangeably, but maybe that's because I went to "<TownName> High School", or maybe it's because I'm old.
- mnw21cam 7y agoThis particular school (the Perse, in Cambridge) calls its secondary section the "Upper School". It's also quite expensive.
- undecisive 7y agoCool post. One small nitpick: > Neil describes his pre-university education as “High School”. We don’t have “High School” in the UK - we call it “Secondary School” Not true at all I'm afraid. Where I'm from (Norwich) we had First / Middle / High School / (Sixth Form or college) splits, alongside other schools that did the Primary / Secondary / 6th split.
- jermaustin1 7y agoI've also seen High School used in Scotland
- dboreham 7y agoCane here to say the same thing, e.g. https://en.m.wikipedia.org/wiki/Inverkeithing_High_School https://en.m.wikipedia.org/wiki/Inverkeithing_High_School Although, there's a subtle difference vs US usage: in Scotland High School is only used in the context of the name of a specific school, not as a term for the generic concept. E.g. "What secondary school did you attend?"; "I went to The High School" (meaning the Royal High School in Edinburgh). You'd never say "What high school did you attend?".
- davb 7y agoEven that point varies regionally. Where I grew up, in Glasgow, it's really common to talk about primary school kids going off to high school or talk about which high school you attended.
- teh_klev 7y agoAgreed. I'm in my 50's and even back in the late 70's in Scotland you'd hear folks use "secondary school" and "high school" interchangeably. I myself went to a Scottish "High School" for my secondary education in the 70's/80's.
- WWWWH 7y agoInteresting, was this when the High school (Glasgow High) was closed? I’m not clear on the dates, but the secondary must of reopened in the early 70s.
- decasia 7y agoIt's impossible to overestimate the power of expectations to create trust (even in the face of contrary indications). This just almost happened to me this week: A couple of days ago I wrote an email to a friend I hadn't been in touch with for several years. A day later I got a message from him on Facebook with what looked like a YouTube link and the cryptic message, "It's you?" I didn't want to see myself on a random youtube video I had never heard of, so I wrote back that I didn't want to click. Then the next day my friend announced that his account had been hacked and that those messages were spam/malware, with a bad impersonation of a YouTube link. But I was so sure it was a legit message from my friend that I didn't even notice that the link didn't actually go to YouTube. Fortunately I never clicked it, but just like the OP, it was blind luck. [edit: fixed wording]
- zubi 7y agoA few days ago, I also received the same message from a friend with a link to a fake youtube page, but unlike you, I actually clicked it despite intuitively knowing that it was malicious. Seemed like a "regular" phishing attempt but I now wonder if it is more than that, having read this article.
- albertgoeswoof 7y agoProbably not a good idea to click a link you know is malicious, you never know what 0-Day they might have
- zubi 7y agoRight. 0-days did not not cross my mind. Until now.
- lhoff 7y agoThat's what I keep my old Blackberry Z10 for. If I get something weird or want to go to dangerous places on internet (for research obviously) I use that thing. I'm pretty sure know one writes a 0-day for a 0.0% market share device.
- matthewowen 7y agoThe specifics of this - the request to judge a prize one is clearly unqualified for - are we as software engineers particularly vulnerable to? Most people would, I think, conclude "this is fake, because why would I be asked to do this?". But I often think that as software engineers we fancy ourselves to have more insight into other fields than we really do. Does this ring true to anyone else?
- pimmen 7y agoIt could be that they're setting up some new category related to tech or something, that would probably be my first attempt to rationalize why they sent the request to me. However, I think that a few minutes later I would've thought "but why would they ask an engineer and not an academic who has done research into this particular technology's contributions to economics?". But, yes, I believe that the fact that software is transforming so much stuff all the time and we developers get to work with experts from all kinds of fields if we're lucky like agriculture, medicine, geology, finance and what not can give us a false sense of actually being an authority on any of the things we write software for.
- WAHa_06x36 7y agoThey were targeting cryptocurrency people, not software engineers. And cryptocurrency people very often have an immensely inflated opinion of their own knowledge of economics, so it's actually absolutely perfect bait.
- jjoonathan 7y agoNearly every contest I've ever competed in has had judges who I didn't believe were vigorously qualified. Perhaps not in the final round, or in the most competitive sections, but they were there, somewhere, filling in the gaps. On the other side of the equation, I regularly got "please judge this contest" emails I wasn't qualified for while I was still in academia. Falling for this phish woudln't need to be a matter of inflating one's opinion of oneself, it could simply happen by knowing that at the low end of contests, the bar for judging is low.
- wutbrodo 7y ago> Does this ring true to anyone else Not to me, and that jumped out at me as the most bizarre part of the story. I have a lot more of an economics background than "having read some Paul Krugman articles", but I'd think that this was obviously a scam because there's no way in hell that that anyone in the world would think I should be judging a competition on economics.
- scotchmi_st 7y agoThis is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn't already been tried, perhaps it's worth building a spam-blocker which checks for bad grammar and increases the spam score for every mistake found.
- djaychela 7y agoI read in the past that this was intentional - it's a filter to ensure that people who are inclined to note detail pass up on the offer, meaning they only get the most likely prospects to be ripped off.
- bonyt 7y agoThat’s likely true for the Nigerian prince scammers, but when they’ve got a browser zero day, they can successfully attack people that aren’t suckers.
- davb 7y agoTrue, but we don't know the next stage of their attack. Perhaps after compromising the target's machine the attackers would have to then engage in some social engineering.
- ryandrake 7y agoI suppose it's easy to "Monday Morning Quarterback" this one, especially after we now know it's a hoax, but honestly this is more fuel on the fire of: Never respond to random people on the internet asking you for information or to do something. Random people knocking on your door are almost always selling something, and random people contacting you over the Internet are almost always scammers. The story could have ended at "I wouldn’t say I’m an “expert” in economics exactly". Then why are you going and doing what this rando is asking you to do? Deep six the E-mail and move on with your life.
- CPLX 7y agoThat's just really not true. Especially not in a professional setting. I deal with this personally all the time, as the founder of a national conference series. We reach out to people cold all the time and invite them to prominent speaking roles. Sometimes people are surprised to hear from us or don't think of themselves as public speakers but we're most certainly real and serious. I get it the other way all the time now too, people reaching out wanting to partner, work together, have us write articles about them, whatever. These are all super common use cases. There's a lot of business that gets started by an introduction from a random person on the internet.
- mnw21cam 7y agoYeah, so I have published a few journal articles. Nary a day goes by without receiving multiple emails begging for me to speak at a conference (invariably in China), or submit another article to their particular journal (that I have never heard of before). So, you can understand why cold introduction emails tend to get redirected to /dev/null.
- ryandrake 7y agoAs is true for most HN posts, I should have prefaced with “In most but not all cases...” People who do not happen to be conference organizers or frequent recipients of legitimate cold calls should, in most cases, ignore unsolicited messages from strangers.
- barking 7y agoI presume that I can I take it from the lack of comment on the Firefox angle that there are no concerns that Firefox is inherently less secure than Chrome?
- larrik 7y agoChrome had a nasty one back in March, so your presumption seems correct. Really, the best way to protect yourself is to use an obscure OS, or a separate machine for web browsing. Sounds paranoid, but the web is THE main attack vector these days.
- mnw21cam 7y agoThere are disadvantages to using an obscure OS too, in that it is likely slower to get security fixes, and may have more security flaws.
- albertgoeswoof 7y agoThe only logical answer is to write your own OS The ultimate security by obscurity
- danieldk 7y agoYou could use something like NixOS, which has interpreters, libc, etc. in non-canonical paths. And you still have the protections of Linux and speedy security updates. Of course, this is security by obscurity, an attacker could adjust the malware for such cases.
- 2a96eb7d685a49c 7y agoYou could use Qubes OS[0] which will allow you to isolate different aspects of your computing into separate VMs easily. [0] https://www.qubes-os.org/ https://www.qubes-os.org/
- veeti 7y agoOr disable JavaScript, which is the cause of most RCE exploits.
- throwayEngineer 7y agoSo for this, you need to be using Firefox and Apple/Linux?
- tempodox 7y agoSystematic dropping of definite article makes me suspect the author may be a native speaker of some eastern language with limited knowledge of English.
- albertgoeswoof 7y agoIt’s odd that they would have limited knowledge of English yet understand the prestige of Cambridge, be able to create genuine looking linkedin pages and target the attack so well. If you’re going to that much trouble running a spell checker over he email would seem like a reasonable step? Most likely it’s a deliberate attempt to target people who are excited enough by the email to not notice the grammar.
- fwip 7y agoForeign language speakers aren't stupid. You can Google "famous school England" in any language. There's no "second step" to this con. You don't have to get tricked into wiring them money. If you visit the page, you lose.
- albertgoeswoof 7y agoExactly, they’re not stupid. So you’d expect them to use a spell checker if they intended for the attack to have a high success rate on English speakers. There may have been a second step for the attackers goals after the zero day, e.g. ransomware or some other social engineering
- tempodox 7y agoA spell checker still doesn't detect faulty grammar.
- ndiscussion 7y agoA sufficiently good one does, grammarly being the most well-known example I'm aware of.
- pierlu 7y agoI think the real moral of this story is that (like the fun vulnerabilities on Flash and Java that we might remember), a combination of keylogger or strange daemon might be running suddendly on your machine, scanning your files, either on OSX or Windows. Simply visiting a website. So better (as said) is to use a separate VM to access trusted domains (and yes, also VMs aren't these days so trustable). Better to use 2FA and ciphering on-disk sensitive info and loose the habit (if any) of storing a large number of files that streams from locally mounted cloud accounts, like Google file stream, Onedrive files-on-demand and so on.
- danieldk 7y agoSo better (as said) is to use a separate VM to access trusted domains (and yes, also VMs aren't these days so trustable). I would use the VM for accessing untrusted domains. If an exploit has your host system, then it also has the trusted VM. ciphering on-disk sensitive info If an exploit has root-kitted your system, encryption does not help much. Presumably you have the unencrypted volume mounted, moreover, the attacker could log keystrokes. If your machine is compromized, it is basically game over. Change all your bank accounts, e-mail, etc. credentials immediately, wipe the disk. By suspicious about any file the malware may have touched.
- kazinator 7y ago> But all it would have taken is for the attackers to add the 7 words “THIS PAGE MUST BE VIEWED IN FIREFOX” to the top of their page, and I’d have been toast. Unless you were smart and ran the NoScript extension or something similar. Landing into malicious pages happens; you're not going to avoid it with 100% accuracy and have to be prepared with some sort of countermeasure.
- fencepost 7y agoThe two questions that immediately jumped to my mind on this are 1) does Coinbase's user base skew more towards Firefox than the average, possibly because of perceived better security/privacy and a desire for that among cryptocurrency users? 2) did the zeroday impact Tor browser users, and does Coinbase have a lot of those?
- easymodex 7y agoI don't think Coinbase users are looking for security/privacy. To be specific, Coinbase is considered a novice cryptocurrency user platform since they have some relatively hefty fees in exchange for being simple to use AKA "It's for normies".
- hotdogs 7y agoThe original spearphishing targeted Coinbase employees, not their users. It seems once that failed, the people behind this cast a wider net.
- pjdemers 7y agoI thought 0-day exploits could be sold for a significant amount if money. I wonder if the hackers bought one, or, found one and thought they could make more on their own than by selling it? And, if they did buy one, what was the return on their investment?
- nemothekid 7y agoI may be making things up, but I remember reading the particular bug was reported by a white hat to Firefox’s internal bug tracker and somehow may have gotten leaked.
- zrobotics 7y agoIf the 0-day can be sold, then what do the purchasers do to recoup their investment? Aren't attacks like this one of the main reasons that a 0-day will have value? Even malicious state-level actors will likely use the purchased vuln in an attempt to gain access to a target system (potentially via similar spear-phishing methods); although in that case their motivation will be access to information rather than financial gain.
- stordoff 7y ago> Looking back it’s obviously completely absurd that the University of Cambridge would ask me to judge an economics competition I don't think this really matters all that much. I might click the link anyway to find out what it is, or to find out why I am allegedly being considered, or even just out of general curiosity. It doesn't _stop_ the attack from working.
- jjwhitaker 7y agoI think a process like with unwarranted phone calls is in order. Take the name and contact info provided but Google for the information yourself and contact the official site/email/phone number for information.
- safetyfirstb 7y agoA word of warning: go to the actual site and find the contact details there. I've seen an attacker change the contact details listed on Google search results (the ones that appear in the boxes) to their own. I saw it used as part of a Windows help center scam, but I don't see why it wouldn't work here too.
- jjwhitaker 7y agoThat is what I had meant but not how my wording ended up. Verify the contact info from the vendor/firm's site itself if possible.
- miles 7y agoA case of "flattery will get you everywhere": > I received a very flattering email from the University of Cambridge, asking me to judge the Adam Smith Prize for Economics ... > I wouldn’t say I’m an “expert” in economics exactly, but the university’s request wasn’t that surprising. I do have a subscription to The Economist ... > I’ve read a few books by Paul Krugman, but aside from that have never studied or practiced economics
- proactivesvcs 7y agoWhich, in my experience, is not a typical tactic employed by phishers. Usually it's greed (Here's $50 million for you) or alarm (You've been hacked!).
- mrmattyboy 7y ago"Neil, if you are real and this is your real LinkedIn profile then I am so sorry. But if you’re so real then why did you copy someone else’s self-description?" I would love to find out that the profile _is_ real, and that the JPMorgan dude is actually a fake profile for another scam (for trying to cheat people out of money), who stole this guy's self-description :P The beautiful outcome being that he'd have publicly shamed and picked apart the guy's entire profile and foiled another scam in one hit :)
- ponyous 7y agoHow can I check if I am infected?
- iandanforth 7y agoNote for the nitpicky, the attack discussed made use of not one, but two 0-days to accomplish the sandbox escape. https://www.zdnet.com/article/mozilla-fixes-second-firefox-zero-day-exploited-in-the-wild/ https://www.zdnet.com/article/mozilla-fixes-second-firefox-z...
- jbigelow76 7y agoI'm seriously thinking a dedicated Docker container just for reading email is a pretty good idea.
- hdfbdtbcdg 7y agoHow would that help?
- 0xffff2 7y agoIt would mean you need an additional vulnerability to escape the VM sandbox.
- hdfbdtbcdg 7y agoYeah if you check email in a VM. But how would a Docker container help?
- 0xffff2 7y agoMaybe I'm using terms interchangeably when I shouldn't be (I haven't jumped on the containerization bandwagon), but a Docker container is still just a "VM light", right? Part of its purpose is to isolate the things running inside of it from anything else running on the system. I'm fairly certain my comment still stands if you just `s/VM/container`.
- hdfbdtbcdg 7y agoNo. Docker isolation is for convenience not security isolation.
- starman100 7y agoThis "spear" was also for a MacOS vulnerability. No doubt most Mac people think they're immune to viruses and malware, making this even more effective. It is very well thought out attack.
- panpanna 7y agoA lot of recent high profile targeted hacks have been against macos (poker stars, Saudi activist, Chinese activists, ...). Let's just agree that all platforms are vulnerable and anyone telling you otherwise should not be trusted.
- closeparen 7y agoAll platforms are vulnerable; it does not follow that running commercial anti-malware products is good idea, or even likely to make you less vulnerable, on every platform, which is the usual context for "Macs and viruses" arguments.
- dheera 7y agoFunny that the browser that has been selling so much on privacy falls victim to such a vulnerability. In any case, if a site says "this site must be viewed in Firefox" that would be a huge red flag, and all the more reason for me to leave. There aren't really any features in Firefox that other browsers don't have.
- feanaro 7y ago> Funny that the browser that has been selling so much on privacy falls victim to such a vulnerability. All browsers fall to such vulnerabilities -- Chrome had one in March this year. The difference is that some browsers (again, Chrome) are malicious by design instead of only by accident.
- 0xffff2 7y ago>Funny that the browser that has been selling so much on privacy falls victim to such a vulnerability. How so? Privacy is not inherently synonymous with security.
- deleted 7y ago[deleted]
- noja 7y agoSo did the attackers get control of a Cambridge e-mail account and web page?
- jakejarvis 7y agoThat was probably the easiest part of their escapade, sadly — spoofing a WiFi access point with a fake portal comes to mind. Or posing as IT and mass-emailing the university directory (which are rather easy to scrape at most universities), keyloggers on lab computers, etc. Always possible that it could have been as simple as just asking! Out of ~20,000 students and ~10,000 staff, they only needed to get lucky once, unfortunately.
- ejstronge 7y ago> The joke was at least partially on them, since I’ve never owned any cryptocurrency other than a handful of Stellars that I got for free and have lost the password for. If they or any other attackers can help me get them back then I would be very grateful. This also happened to me - and after returning to the Stellar site years later, my old login did not work, and the page looked nothing like it used to. Were the free Stellar tokens ever really granted?
- uj8efdkjfdshf 7y agoThat's interesting - there is indeed a grh37 at Cambridge but he's an undergraduate studying Chemistry at Selwyn. No idea about how that happened, but there's been a bunch of really poorly written Emotet/Heodo spam emails floating around the email system the past few years. I'd guess that he managed to get his account compromised while logged into Windows on a UCS computer (which would be a feat in itself, given how poorly written the first stage dropper is), his UCS account got compromised, and someone uploaded the malicious website to his public_html folder. EDIT: Apparently they've blocked new user signups for DS-Web, but this is kinda pointless given that every new student is automatically given their very own live website until they graduate.
- js2 7y agoI thought myself fairly well informed about macOS, having run it since the 10.1 days, administering it over the years, etc. But TIL that the quarantine bit and gatekeeper which normally prevent unauthorized executables from running is trivially bypassed, as was the case in this attack. My paranoia level has increased. https://objective-see.com/blog/blog_0x43.html https://objective-see.com/blog/blog_0x43.html https://speakerd.s3.amazonaws.com/presentations/9e724ea233434f9fb083bff26bc7fb4b/ShmooCon_2016.pdf https://speakerd.s3.amazonaws.com/presentations/9e724ea23343... Yeesh.
- ultrarunner 7y agoI just checked my login items and found runChmm, adware that was apparently installed as part of an FTP client used at work. I was trying to replicate a scenario we see at work and got adware. Paranoia level increased indeed.
- asveikau 7y ago> gatekeeper ... is trivially bypassed It's almost as if they waste a legit user's time, and developer's nominal fees on certs, notary, etc., for something that malware will not actually be subject to. Maybe that's a little disingenuous as Apple can work to close gaps, holes and bugs.... But when it doesn't actually stop malware in the real world and honest people need to jump through hoops, the cynic's reading is easy to make. Similar discussion to be had around DRM.
- Dylan16807 7y agoThere are valid points about being tricked here, but it's all kind of irrelevant in the presence of a javascript 0-day. You don't actually have to trick anyone to use one of those; just make an interesting post on tumblr and away the hacks go. Trying to never get hit with a 0-day is a pipe dream.
- somebodythere 7y agoIf you have a significant amount of cryptocurrency, get a hardware wallet.
- MarMcAdoo 7y agoShould you ever require the services of a hacker, I implore you to try your best to hire professionals only. HACKKINGZEUS@GMAIL.COM will increase your chances of getting a successful hack. I can boldly say that he's an elite, asides the fact that I was provided a permanent solution to my credit and debt issues, he also rendered a very efficient customer service experience as he carried me along every single step of the process and didn't leave me in the dark. He's also available on 407-900-6299. Get in touch with him and be glad you did.
- dan-robertson 7y agoOne thing the article goes into is all the signs that the mail was fake. I think focusing on how one can spot such attacks is slightly silly for two reasons: 1. If these errors caused attacks to be unsuccessful then I expect (competent) attackers would stop making these mistakes 2. Plenty of real people make spelling errors or write single sentence paragraphs or even plagiarise things (or have their own descriptions plagiarised). Real people also host group things on personal sites. I think relying on this sort of thing is too likely to lead to false positives (and its a lot easier to spot the “signs” once one knows the email bad) and too unreliable in the long term for reason 1. One thing I wonder is how this sort of thing might be prevented. It seems that once one’s pc is compromised there isn’t much one can do; newer security mechanisms like security keys don’t help much if the device is compromised. I don’t know how hardware bitcoin wallets (or similar devices) work so I can’t say whether they might have protected the targets of this attack, although I would guess they would not. Sometimes I wonder if this is something there should be insurance for, but would anyone buy it? I think it would have to start as insurance for companies (which would require large numbers of companies to consider a breach like this a major financial risk) before people but such attacks would have to be unlikely enough to be successful for the insurance to be cheap. I suggest insurance with the vague hope that an insurer would want their customers to be more secure to decrease the chance they have to pay out. I don’t know if it would work that way in practice.
- rmtech 7y agoA hardware wallet is safe even if the computer is hostile. That's why they exist! However it's possible that some other attack method could be used, e.g. compromising the user's email account and going from there.
- myrandomcomment 7y ago<soapbox> Every time I open the UI for the Ubiquiti UniFi console in Safari it complains that Safari may not work correctly and suggest Firefox or Chrome. Every time I curse at it, ignore it and have had no issues. The simplest way for me to not do want you ask is for you to tell me best viewed in X. If it does it working in Firefox, Safari, Chrome and Edge, then £#&$*=+&$% you. Do your job and test on the major platforms. My current company has a web UI and I make it a point when using the product to open it in a different major browsers each time I touch it. If there is an issue I file a Jira ASAP vs the UI team. </soapbox> Okay I know this is about the Firefox security bug, but just a general rant anyways.