3 ms·
sorry to hear that. I don't exaggerate, but the unfortunate part is there is a lot of FUD out there- I just had a friend install nordvpn because someone sent he
by ipython 2y ago
sorry to hear that. I don't exaggerate, but the unfortunate part is there is a lot of FUD out there- I just had a friend install nordvpn because someone sent her a gift card scam email to her business email address. So there's a lot of misinformation out there, mostly from folks selling product.
Password management is one of those fundamental security foundations- essentially serving as the 'root of trust' for your own personal digital life. If you mess that up, you're in for a world of hurt. I don't mess around with passwords. Taking your analogy, would you intentionally stand outside under a tree in a thunderstorm, figuring that the risk of getting hit by lightning is so small?
- Gigachad 2y agoIn this situation, the attacker had to know you were using this particular password manager, know roughly when the password was generated, reverse engineer and replicate the password generation algorithm, and make millions of login attempts somehow (almost never possible other than on crypto wallets). Yes it’s obviously not good that they used the date as a seed, but the realistic risk is pretty much non existent. Even in this case where literal millions of dollars were on the line the “attackers” still had to collaborate heavily with the owner to narrow down the search space. On their own they likely would never crack it. Absolutely no one is going through all this to get in to your Facebook account when they can just call up some grandma and ask them to transfer a $1000.
- ipython 2y agoYou've shifted the goalposts here. You're right that this all comes down to economics. You're not going to go to these lengths to break into a Facebook account -- however -- you have to remember that there is a lot of transitive trust nowadays. So that Facebook account may allow you federated login to something you do care about. Or your Facebook account is the front page for your business, where a defacement or outage could cost you thousands of $$$. Or you reused your Facebook account's password as the password for your email, which probably was the recovery email for every online account you have... meaning you can now log into every service given access to your email. Real security is about threat modeling and risk mitigation. Risk mitigation is simply the application of a rough economic model of both the attacker and defender to find a median where you are comfortable. Essentially a fancy way of determining how fast you need to run so that the bear eats the slower person first. Your example is apt- the grandma who is scammed out of $1000 is running much slower than the grandmas who were not, all things being equal. So when it's "just" a Facebook account on the line, yes, nobody is going to go through massive effort to crack it. But that's not what the original post was about - it was about unlocking millions of $$ worth of Bitcoin. That's worth some effort. Remember also that, in this story, the person who retrieved the password does not end up with 100% of the proceeds, as you would in an adversarial scenario. In the adversarial scenario, the adversary's risk calculus is vastly different and they would be willing to spend a lot more effort (time, money, resources) into cracking that password.