10 ms·
Someone is stealing unpublished book manuscripts in a phishing scam
- deleted 6y ago[deleted]
- andreareina 6y agohttps://archive.is/5BESy https://archive.is/5BESy
- lioeters 6y agoThat one didn't work for me, but this does: https://outline.com/JWdxDm https://outline.com/JWdxDm
- mosselman 6y agoIt is almost as if e-mail isn’t a secure medium for communication... Look, I am not a security expert so please correct me if I am wrong about any of this: Every time PGP for the masses is suggested as a solution it gets dismissed as being to complex or difficult to wrap your head around, but all these scams would not work in a world where authors and publishers only trust signed e-mails. In my mother’s case I am sure pgp is too complex, but shouldn’t we demand it in a professional context? Whenever some company gets socially engineered through e-mail the response is “we were targeted by a super tailored phishing attack, bla bla” as an excuse for digital negligence which not using digital signatures for e-mails basically is. Or are there things I am overlooking?
- ed_elliott_asc 6y agoYou aren’t, also of email clients show the actual from address then it would stop most of these.
- nobody9999 6y agoDigital signatures definitely could have helped. However, the email addresses/domains were very carefully chosen, as was the text of the emails. It's pretty clear that whoever is involved either knows most of these people or had extended access to their emails. You should read the article.
- g_p 6y agoAs tech savvy users, showing actual from addresses would be a big step forward from the modern trend (thanks, Apple?) of showing only the display name of the sender. Sadly recent versions of thunderbird seem to default to this as well, but an extension fixes that. The problem for most users is that they won't recognise people's email addresses as signal - it's just noise to them. They don't know how to parse a domain backwards from TLD/ccTLD to determine where it goes, and even if they did, homographs and other international characters can fool them fairly easily. Maybe the solution is something like SSH with trust on first use? Where users get alerted to a new display name and are asked to approve it the first time they send an email. Then a bundle of sender email, DKIM/DMARC/SPF success is stored locally, and future emails need to match that, otherwise the user will be warned this might not be the right user. It seems without cryptographic identities (vouched for through PKI, a la S/MIME) that this is a hard problem to solve when you take into account the human factors and how much the existing solutions rely on the user.
- hansvm 6y agoIn a lot of contexts I wouldn't mind an explicit whitelist. If somebody wants my email, they can let me know ahead of time how they'll be using it, and I can grant them permission to send me emails from a given source. Combined with DKIM et al it would eliminate many classes of phishing attacks and also deal with the email harvesting and spam problem.
- g_p 6y agoI can definitely see this working for tech-savvy users on additional accounts. The problem with email is that it's still used/needed as the "universal" online way to establish/initiate correspondence with someone. It's become used for person-to-person communications, as well as computer-to-person communications, and is probably one of the few standard, interoperable, near-ubiquitous means of reaching people, short of postal mail and carrier-provided services like SMS and voice calling. While requiring people to know who they want to correspond with before the fact could be helpful, it also breaks a lot of popular use-cases for email - email is often written into contracts as a valid means of serving notice etc pursuant to the contract. Locking email down to only receive mail from approved senders would break a lot of things, but certainly help to prevent this kind of spam. I wonder to what extent this could be reduced however by using unique per-use aliases - in a sense you can get a softer version of this whitelist by giving out per-sender inbox aliases, and therefore seeing which alias was used to send a message. Not quite sender authentication, but perhaps better than nothing. Doesn't prevent compromise of the underlying (human-to-human) email address, but would certainly help with a lot of phishing-type scenarios using breached customer records.
- raverbashing 6y agoPGP is not the only solution, therein lies the answer Prosecuting the people that do this is also a way of helping with the problem, acting like a coward and paying extortion money only makes you an easier target
- londons_explore 6y agoIt's time privacy sensitive governments started doing something about the lack of privacy in email. How is it acceptable that my email to Bob Smith can travel across the internet unencrypted with my and his name plastered on the top? Thats a privacy problem! The EU regulators should fine anyone who sends an unencrypted email within the EU... Start with big mail providers to get change in motion.
- raverbashing 6y agoIf your email goes between the major email providers, it goes encrypted. (At least according to the headers)
- londons_explore 6y agoIt goes encrypted, but hardly anyone checks TLS certificates on SMTP connections. That means you're not safe against any ISP on the route who could simply proxy with a self signed cert... Thats barely better than unencrypted.
- raverbashing 6y agoHardly anyone who? Email clients are supposed to check or they're internally bound (Gmail web client etc). Yes I think you can bypass the checks but doesn't mean they aren't checked
- londons_explore 6y agoServer to server connections. Eg. Gmail.com sending email to cnn.com. That would be TLS encrypted, but the server certificate wouldn't be checked.
- kmlx 6y agois this satire? Can’t tell due to how strange these forums have become in the past few years.
- watwut 6y ago> In my mother’s case I am sure pgp is too complex, but shouldn’t we demand it in a professional context? Professional context is tons of people like your mother. But also, PGP web of trust would break in larger adoption.
- Galanwe 6y ago> But also, PGP web of trust would break in larger adoption. Agree with you. My guess is very quickly people would start to ultimately trust all they friends and colleagues. There would be phishing bots to convince you to trust other bots and fake profiles, etc.
- foolmeonce 6y agoIn cases like this it doesn't matter so much, this attack wouldn't even work over LinkedIn's web of trust.
- Galanwe 6y agoWhy wouldn't it? If you ultimately trusted a colleague that was phished into trusting the attacker, then you would trust the attacker to be who he claims to be.
- foolmeonce 6y agoThey would need less believable stories and to impersonate interns, subcontractors, etc. The pattern in the attacks could be extremely brazen, like impersonation of the editor themself or a higher position colleague to resist social checks. Pretty strange for a long term editor to have few paths to themselves within their own publisher. (Since each attempt to gain a new connection in the publisher risks someone noticing the email address is a fraud of their own company and cause revocations.) If the attack is 100 or 1000 times less effective it is probably written off as a complete waste of resources.
- frereubu 6y agoI always have a wry smile on my face when I read the lazy assumption that a large proportion of the workforce is not made up of large numbers of “someone’s mother” or “someone’s grandmother”, let alone the fact that for some reason it always has to be a woman in these contexts.
- andi999 6y agoPGP might make the scams worse where the account was taken over (and then help me email send out)
- eznzt 6y ago>but all these scams would not work in a world where authors and publishers only trust signed e-mails. It would be like https: worthless because of Let's Encrypt
- alsetmusic 6y ago> It would be like https: worthless because of Let's Encrypt Can you please elaborate why LE.org makes https worthless? I don’t want to make improper assumptions as to your meaning
- pacamara619 6y agoThis analogy is flawed in two points: 1. Let's Encrypt isn't useless because 2. With certificates you can be sure, the message you received, is from the certificate owner. This applies to websites and emails.
- eznzt 6y agoThe point here is that I could sign any email as long as I control the address. The fact that an email is signed does not mean it's to be trusted. Same with https.
- merlinscholz 6y agoFrom where would you get the private PGP key of the person who owns the email address?
- eznzt 6y agoThat is not what the comment says. The comment says: >but all these scams would not work in a world where authors and publishers only trust signed e-mails. Not that people will take the time and effort to verify the signatures. Not to mention that you can still call them and say "eeeh I'm Jones, you know, I just had to renew my signature, so it won't check, but it's me. bye"
- throw14082020 6y ago
- amelius 6y ago> all these scams would not work in a world where authors and publishers only trust signed e-mails. Minor nitpick: signing is something different from encrypting, and in itself would not protect against eavesdropping.
- MaxBarraclough 6y ago> In my mother’s case I am sure pgp is too complex, but shouldn’t we demand it in a professional context? HTTPS has been successful in being both highly secure and requiring no real attention (or technical knowledge) from the average user. Could this not be done with email too? Isn't this a job for the IT department rather than for the user themselves?
- jpxw 6y agoThe (rough) equivalent of HTTPS is DMARC/DKIM. It doesn’t solve this problem, in the same way that Amazon using HTTPS doesn’t stop people visiting non-Amazon phishing websites.
- jpxw 6y agoHow would digital signatures fix this problem? The issue isn’t that mail is coming in with fraudulent From headers - my understanding is that that is very rare these days, thanks to DMARC/DKIM.
- helsinkiandrew 6y agoIf a person gets fooled in responding to email from another account then I'm not sure they'll be protected by pgp. What's really needed is for email clients to clearly say who the email is from - is it a new account, have they got email from the same domain etc.
- jpxw 6y agoYeah, it seems clients are lagging behind with this. Visually marking emails which are from new domains or addresses is a nice idea. The From header should be much more prominent too. For example, perhaps a user should be presented with the email address in large text and explicitly asked to “trust” it before viewing emails for that address (similar to SSH). People would probably get fatigued of that and click through though, of course (similar to SSH... although it’s much easier to quickly check whether an email address is as expected compared to a SSH fingerprint).
- 0xbadcafebee 6y agoThe client doesn't have to implement it, you can write a plugin for most clients and charge $$$ for businesses to install it. The fact that it's not been done yet is just a missed business opportunity.
- helsinkiandrew 6y agoThe people who need it won’t understand what it does or why they need it and are unlikely to buy a plug-in.
- sebmellen 6y agoCheck out https://vereign.com https://vereign.com. One of the portfolio companies of CV VC, very solid tech.
- hshshs2 6y agothe problem is social engineering, no? there’s not much you can do about that technically unless you want to implement some sort of authoritarian internet ID system
- giancarlostoro 6y agoWhats worse is it doesnt have to be complex if all standard email clients let you manage PGP keys in a simple and user friendly context with an option for ‘advanced settings’ just give users a padlock icon and show any emails not sent using PGP with a padlock thats red if they go over HTTPS. Hell something like Signal for email could work with its forward secrecy I am not saying Signal itself just the approach. I am still sour that KeyBase got sold off I was hoping they would add an email client and we could all get @keybase email addresses and they would charge for the service finally. I would easily have given them $15 a month for a small family plan (for me and my wife) just cause KeyBase is beautifully done. It could probably be fine tuned but it was great. Edit: Please if someone from KeyBase ever reads this, please make your efforts open, some sort of open source foundation that fully owns the rights to KeyBase and is allowed to later on go commercial. It's a damn shame a decent tech is going to just perish. Do not open source it when it is far too late! All your users who know you've sold off the project have no strong confidence in it anymore.
- opticbit 6y agoHaven't looked into it enough... https://keys.pub/ https://keys.pub/ not sure if you can self-serve.
- fractionalhare 6y ago> Every time PGP for the masses is suggested as a solution it gets dismissed as being to complex or difficult to wrap your head around, but all these scams would not work in a world where authors and publishers only trust signed e-mails. No, that's not why it's dismissed. Security experts don't advocate for PGP for two reasons: 1. It requires constant vigilance. If humans en masse were capable of constant vigilance in a security context, we wouldn't really have a problem with phishing in the first place. 2. PGP uses relatively old cryptography which is easily misimplemented and doesn't feature forward secrecy. So again to maximize security you have to rely on your users doing something manual: in this case, generating and sharing new keys at some interval, which then need to be verified on the other end etc. Speaking to the more general point on phishing: people on HN are usually very overconfident in their ability to spot phishing emails. It's easy to spot simple ones reliably. It's fairly easy to spot pretty good ones when you're expecting it. It's functionally impossible to consistently spot very good phishing emails. I say this as someone who has run simulated phishing email campaigns on software engineers in a large tech company. Even many security engineers would get caught out by the best phishing emails, and what's worse: the set of engineers who would be fooled would change depending on the day you ran it. Humans are fallible. Attackers do not need to compromise most people in your org. They need just one person with privileged credentials to have an off day and not run through an unrealistic checklist, in an organization with hundreds to tens of thousands of people. The best phishing emails will combine excellent social engineering with a legitimate technical break that privileges them to send email on behalf of a domain. You will not spot this reliably, no matter how technically savvy you are. It will pass the technical checks you have. The best approach to mitigating phishing campaigns is endpoint security. You should obviate the need for employees to even use passwords in a corporate context, and you should use authentication systems which aren't phishable.
- AuthorizedCust 6y ago> You should obviate the need for employees to even use passwords in a corporate context, and you should use authentication systems which aren't phishable. What are best practices or products for this?
- 6y ago
- plif 6y agoNot just email / text comms -- it's not hard to fake voice and video now either. Maybe PGP in its current form is too complex for your mother, but that is one of the reasons her generation needs it the most. I agree that it's a no brainer in a professional context, however I can see there being a ton of value in having a simple / cross-platform / cross-medium personal signing mechanism as well. It's something that we could have used yesterday.
- grawprog 6y ago>It is almost as if e-mail isn’t a secure medium for communication... Have humans ever had a truly secure medium for communication? As long as we're communicating, there's always a chance our communications can be intercepted in some way by a third party. Whether in the physical world or digital world. >Or are there things I am overlooking? The human factor. You can have all the security in the world, all it takes is for one person to slip up once. Maybe the person answering the email was in a rush? Maybe they were tired and didn't really pay attention? Maybe someone was talking to them while they read the email and they were distracted and didn't notice it seemed shady?
- toast0 6y ago> where authors and publishers only trust signed e-mails. Signing emails isn't the problem. Establishing identity is the problem. Where I worked, there were a lot of phishing scams going out. Initially, they spoofed our email address, and DMARC helped stop that; but people would still respond to scams coming from webmaster@johnshouseofcontracting.example.org or whatever (lots of random website email forms turned into open relays). If you're getting emails from publishing@randonnhouse or wi1ey or whatever lookalike domains, it's going to be hard to tell, and verifying it came from the someone authorized by the domain owner doesn't help.
- scandox 6y agoAlmost certainly a super fan of some kind. The Literary business world is all about insider info, gossip, worthless prestige of one kind or another. If I had to guess they sat down to write their novel and this is the ultimate act of procrastination.
- gkoberger 6y agoSince (so far) nobody has been harmed, this is such a fascinating little story. It reminds me of the Adam Pisces episode of Reply All: https://gimletmedia.com/shows/reply-all/z3hgd2 https://gimletmedia.com/shows/reply-all/z3hgd2 My best guess is it's just bored people with private collections, similar to how people were privately collecting and trading pictures off celebrities iClouds (before they were all leaked publicly).
- gwern 6y agoOr the recent Twitter hack: they hacked the most famous people in the world like Jeff Bezos, all because they were powered by people obsessed with getting, of all things, usernames like 'A' etc. Who would dare to write that up as a serious proposal for how computer security would work in 2020? And yet... (I take it as yet another example of Littlewood's law: https://ww.gwern.net/Littlewood https://ww.gwern.net/Littlewood )
- cstross 6y agoMost likely a super-fan. The only possible nefarious scenario I can figure out is: phisher is connected to a more dodgy publishing outfit -- either piracy sites that offer access to PDFs of books for a monthly subscription, or (much less likely) a not-very-scrupulous publisher in a foreign language territory who would like to publish a translation without paying royalties and before their Anglophone population get access to the official ebook (this is a thing, it cannibalizes translation sales in markets with a big English-literate population). (Ebook piracy sites are a pain in the ass: I've seen novels that I've written advertised for download before publication date, presumably because somebody leaked an early review copy, complete with pre-edit typos.)
- harshreality 6y agoWhy would a super-fan be targeting so many authors? I could imagine one, or a small group of, obsessive book collector(s) trying to collect obscure literary content within a narrow focus or genre, but I have trouble believing they'd put so much effort into acquiring drafts by a seemingly random assortment of authors. I'm partial to your nefarious scenario. Or here's another one: GPT-4 has escaped the lab and is collecting more material to learn from in its quest to be the world's best predictor of human narratives.
- aaron695 6y agoI like the idea it's someone testing if GPT-2 can phish. There's a few GPT-2s running around.
- 3np 6y agoGiven the level of dedication of some completely (at least seemingly) non-profit piracy groups make me think it may be a small release group gone just a bit too far.
- cstross 6y agoThat's entirely possible. But don't discount covert monetization channels, such as supposedly "free" download sites that provide a vector for bitcoin miners and other malware.
- deleted 6y ago[deleted]
- poma88 6y agoIs this news? And if so, why bad news?
- dxdm 6y agoIt's interesting to me to learn about novel targets for phishing attacks, and it's probably even educational for book authors and other trusting folks to learn that they can be targeted this way. The answer to your second question of course depends on your own idea of what constitutes "bad news"; but I think it's not hard to imagine why some people might not consider it a good thing when folks are getting duped into revealing information outside its intended audience. It's curious that I can't resist writing this when you likely already knew and ignored it when you wrote your comment.
- buzer 6y agoTwo possible scenarios come to my mind, but both are a bit far fetched. First one being that this is some kind of phishing training & seeing what kind of techniques could be utilized when doing attacks against high-value targets later (or maybe even being a "final test" in some phishing course for some of the more professional groups (those that are run by nation states)). Another one being that they are doing it to obtain blackmailing material. Maybe they are hoping that there are things in some of the drafts that could be used to blackmail the author (e.g. in some cases there could be things that might be considered to be racist/sexist/similar, but would normally be caught by the editor).
- thimkerbell 6y agoDoes Ian McEwan know what it might be about?
- throw14082020 6y agoB2B companies of HN, how do you communicate with each other privately? I'm struggling to find a secure communication medium. Setting up PGP is annoying and also requires recipients to have it. Emails are clearly not private. Whatsapp, Messenger, Signal and Telegram are a bit personal (most require a phone number, and companies don't provide phone numbers to all people). SMS/ phones are also not secure. LinkedIn premium is expensive monthly and doesn't provide a good messaging UI. Oh, the reason why I ask B2B specifically is because consumer products can communicate through their platforms where users already have accounts. Their either enmeshed in platforms or have their own platforms.
- kwerk 6y agoWire is more popular in the EU but does this.
- deleted 6y ago[deleted]
- ketamine__ 6y agoLinkedIn but not Signal? Isn't this a problem with a clear solution? Use a phone number with Signal.
- cpach 6y agoDo you mean e.g. how company X (vendor) communicates with company Y (client to company X)?
- rohansingh 6y agoI've worked across companies in shared Slack channels. And also linked Facebook Workplace instances.
- PragmaticPulp 6y agoFrankly, focusing on the absolute security of the communication medium isn't a real issue for 99% of business purposes. Phone calls are secure enough for most purposes. At the upper levels of business, e-mail is used for quick notes and corrections, but the heavy lifting is going to happen in phone calls and other real-time communications. Techies some times put too much emphasis on things like cryptographic security of the communication channel or strength of encryption, when in reality it doesn't matter for phishing attacks like these. You could go to great lengths to get your customers set up on Signal or Telegram, but it doesn't matter the second they get an e-mail phishing attack that says "Hey, I got a new phone, locked out of my account, can you just attach the document here?"
- jancsika 6y ago"steal" is a misleading verb here. Even the content of the article agrees with me-- > tricking writers, editors, agents and anyone in their orbit into sharing unpublished book manuscripts This is "copying without permission," "illegal access," or simply "phishing" which everybody in 2021 understands. The sexy but ambiguous "steal" doesn't make clear whether the author still had access to the manuscripts.
- ruddct 6y agoOddly, a version of this is also happening in my wife’s world, but with music composers instead of authors. The scheme is a little less sophisticated, but the themes are the same. The phisher knows the parties involved and their relationships, they know the lingo and the process of commissioning a composition, it isn’t limited to famous/well known people/groups (e.g. they target grad students), and it’s very unclear what they’re attempting to achieve (or how they might monetize it).
- randycupertino 6y agoDoes your wife have a working theory on who or why someone is behind it?
- Iwan-Zotow 6y agoPutin!
- girzel 6y agoEven we translators have been targeted! A couple of my colleagues have sent manuscripts of translated Chinese fiction to bogus editors. If you thought unpublished original fiction was unlikely to be a profitable ripoff, unpublished translated foreign fiction is even more head-scratching. I asked a friend to send me one of the emails so I could look at the headers. All I could get was that it appeared to be sent from an Italian-language webmail setup, no other clues I could find.
- girzel 6y agoI also looked at the (recently-registered) domain name, which was meant to spoof FSG, but couldn't see anything meaningful from whois, etc. I actually knew the FSG editor who'd ostensibly sent the email and wrote to him: he already knew about his doppelganger. He was both confused and slightly amused.
- ezoe 6y agoEven the Japanese authors are targeted and it looks like it's not a cheap job. They researched the author, publishers, the agent, and translator of the book to English and wrote an phishing mails that looks like authentic. The effort and resources they put on this scam doesn't justify for the cost of pirate. Besides, why do they want draft that isn't finished yet? There's only handful of authors whose upcoming book is so valuable and worth leaking.
- tweetle_beetle 6y agoI can't find it now, but there's a new standard to associate a logo image width a domain for use in email, using a DNS record. From memory one of the big certificate providers is acting as the official verifier and there will be a fee, when it comes out of trial. On its own it's a silly little thing, but confidence scans are all about lots of little things which add up to a greater whole. I think it could help those who embrace it. I remember working at a company where someone in finance gave away a large 5 figure sum to an unknown bank account, because a Hotmail address set up with the MD's name, who was on holiday at the time, asked them to do so. They were lucky that their bank agreed to cancel the payment an hour after they made it. This could have helped.
- breakingcups 6y agoI'd give that about as much a chance as the EV certificates had.