4 ms·
>You pulled a statement about behaviour out of thin air, and it wont hold up to scrutiny. Now its being scrutinised, you are dodging it. Why does the most obvi
by idonthack 15y ago
>You pulled a statement about behaviour out of thin air, and it wont hold up to scrutiny. Now its being scrutinised, you are dodging it.
Why does the most obvious and logical course of events require justification? "Most hackers breathe constantly." "Do you have data to support that?"
Maybe you're right. Maybe this "canary" is extremely effective. Maybe everyone who makes a living by breaking security also happens to be dumb enough that they fail to take the most basic precautions to protect themselves.
Even if that's true, there are still more effective solutions that should be used instead of this "canary".
- mootothemax 15y agoWhy does the most obvious and logical course of events require justification? Obviously because what you've written is non-obvious ;) Enough people "hack" by using simple password-reset forms[1]. Whilst I have no doubt that there are plenty of worringly-competent hackers out there, I'd bet that there are also lots of less competent hackers. Taking this through to its logical conclusion: I'd rather know about some of them than give up and know about none of them. [1] http://en.wikipedia.org/wiki/Sarah_Palin_email_hack http://en.wikipedia.org/wiki/Sarah_Palin_email_hack
- jodrellblank 15y agoWhy does the most obvious and logical course of events require justification? It doesn't. Your claim does. The easiest way to "hack" is to install a script and run it, e.g. a traffic sniffer, a wifi encryption breaker, Firesheep, or any one of many vulnerability scan/exploiters. Or to look over someone's shoulder as they type a password in, or to walk up when they step away from their computer for a moment. None of that needs any hacking chops or brains. Most exploits by volume are going to be like these because these are easiest. The next most easy way is to do phishing scams, it needs some chops to fake login forms and bulk email, but it's not massively complex. The hardest way is to understand and find flaws in a system and then exploit them. This is likely to be most successful, but due to the knowledge, effort and skill and sustained interest required, to be the least common by volume. And then above that, people who do the last one "for a living". A canary that squawks against "I made a mistake and some opportunist got into my email" is more likely to go off, and more likely to be useful, than a canary that squawks against "a skilled hacker targetted me and got through Google's security". Metalfrog's claim is that it is more likely that a real hacker would get in, be taking precautions against honeypots, and the canary would be useless. I think it much more likely that an opportunist would be getting in and a skilled hacker targetting something more important instead, and that the canary stands a slim chance of being useful instead of zero chance.