5 ms·
Hackers shoveled snow for company, were rewarded with network admin access
- mikestew 3mo ago”Finally, the company should have enforced a strong password policy that would have prevented our heroes from finding dozens of accounts with “winter2023!” as the password.” Capitalize that “w”, and you’ve got a password that will pass most PWD policies. Why do they think it was “winter2023!” to begin with? In 90 days when the PWD expires, well, it will be spring of the next year, so… The better idea is to require passwords with some real entropy, and get rid of expiring passwords. It’s not 1999 anymore.
- Xeoncross 3mo ago1. Open a web browser and do a search 2. Read until you find a sentence that you like. 3. Use it as your password
- ChrisRR 3mo agoI like the last line of your comment My password is now password
- hnthrow10282910 3mo agoHacked
- daredoes 3mo agoShould have been "use it as your password"
- nickweb 3mo agoThat's cool. Yours comes up as stars (*). Must be a HN thing.
- ndsipa_pomu 3mo agohunter2 doesnt look like stars to me
- jkrejcha 3mo ago"That's the best password ever!"
- alessandroberna 3mo agoNow you might want to open a pr like this one: https://github.com/danielmiessler/SecLists/pull/155 https://github.com/danielmiessler/SecLists/pull/155
- glitchc 3mo agoNot enough numbers or special characters usually.
- chopin 3mo agoI loathe two things in password requirements: special characters and not allowing spaces. C'mon, it's 2026. Require 20 characters and call it a day.
- Xeoncross 3mo ago"password is to long, max length..." (╯°□°)╯︵ ┻━┻
- Volundr 3mo agoI couldn't decide which sentence of Alice in Wonderland was my favorite, so I just used the full text.
- antonkochubey 3mo agoAlibaba Cloud in 2026 lol
- lukan 3mo agoUse one specific special character/number as word separator.
- raffraffraff 3mo agoHow about mixing up band names? Take the end of "Florence and the machine" and mix it with the start of "Rage against the machine" and you now have the totally unguessable "Rage sharing the machine". It's a different machine see?! Nobody would know that!
- NopIdoN 3mo agoThe The but the first The is from The Who
- daledavies 3mo agoThat's crazy! Imagine what The The and The Who would sound like? Not The The and The Who, but the The The and the The Who your comment alludes to. Or would the original ones be called The The The and The The Who?
- samrus 3mo agoI swear if the ghouls running things had abit more decency and allowed people to actually access and controll their passkeys then that would be the future, everyone would adopt it. The experience is so nice with key pair exchange for ssh. Its just that there i have thr security of knowing exactly where my secret is and how i can manage it, its just a file and i can move it like a file Nobody wants the risk of getting locked out because of apple and googles walled garden bullshit
- deleted 3mo ago[deleted]
- James_K 3mo agoLetting users pick their own passwords has always been a mistake. If passwords are needed, the system should choose them.
- alt227 3mo agoExpiring passwords are one of my biggest gripes, and I still see them everywhere
- grg0 3mo agoExpiring passwords and length limits. Why can't my password be a 5KB long? My password manager has no limits. Are people storing them in plain text in 2026?
- mschuster91 3mo agoI wouldn’t trust enterprise internet security boxes to not trip on such long text fields.
- ryandrake 3mo agoAnd content limits. Why can't my password contain the % character? No special characters? What makes a character "special"? Why can't it contain emoji? So many password systems go to great lengths to remove potential entropy and randomness from passwords with their rules. The usual excuse is "blah blah blah legacy systems" which is not a good reason.
- fph 3mo agoPersonally, I wouldn't use anything beyond ASCII in a password. I don't want encoding bugs to lock me out of my encrypted partition or bank account, thank you very much.
- sfn42 3mo agoProbably because there is some mildly decent reason (or very good, I don't know) to avoid them and it really doesn't matter enough to worry about getting around it. Why would you want emojis in your password? It's a piece of text not meant to be seen, emojis are meant to be seen. Just randomly generate some characters and get on with your life. I don't understand why you care about this at all, it's such a pointless thing to complain about.
- mikestew 3mo agoReplying to my own post: wait a minute, why are there so many accounts with the same password in the first place? Oh, because "dozens" of people are tired of changing their password every 90 days, and someone piped up on an email thread (with the subject line: "Changing passwords all the time is bullshit!", I'm sure) and said, "I just set it to $SEASON$YEAR'!'. Easy to remember, fits the policy." And now you have a system that is far less secure than if you just ditched the expiration policy to begin with.
- lima 3mo agoThe company also should have restricted network access to the port in the conference room so that an unknown device like a Raspberry Pi could not make an Ethernet connection from that spot Bad take - the actual problem is that there was a trusted network in the first place. This kind of network access control is trivial to bypass, and trusted devices can get compromised.
- Symbiote 3mo agoIt's not my field, but at least at my work the network can somehow tell the difference between an authorized user and not. It is not simply using the MAC address. A guest device connected to the ethernet port in the conference room has the same access as a device connected to the guest wifi, a staff laptop has it's usual access.
- onraglanroad 3mo agoProbably a RADIUS server setup. Basically staff machines get a certificate to present to the server and the server controls the network. So, if your machine does nothing, it's on the guest vlan and has limited access. If it presents a valid certificate that network port is reassigned to the staff vlan and you get full access. If someone leaves, you just revoke the certificate and they have guest access again. Not rocket science once you know it :)
- lokar 3mo agoStill better to do that same thing (cert based auth) at the application layer instead of the network layer.
- onraglanroad 3mo agoYes, you can do it by MAC address instead but that can be changed so you can spoof a legitimate device. Edit: oh wait, you mean have the applications check the certificate? Yes, but then you need support from the application. Does your printer do that, for example? You need to make sure everything does. You can of course do both.
- z3ugma 3mo agoWhat always gets me about these red team attacks is the same thing that gets me about internal phishing test emails. My company sent an internal phishing test last week. Several people immediately reported it to a cybersecurity engineer, posted about it in Slack, saying they were surprised that such a sophisticated phishing attack was happening. I too was surprised - Google is usually much better about catching these kinds of things in the GMail filter before they get through. Oh well, sometimes one slips though. Reported it and moved on Come to learn that the only reason it made it through is because we let it through _on purpose_. By analogy to these red team attacks: _theoretically_ someone could rent a car, pose as an employee, and set up a Raspberry Pi in the network. But who would go to all that trouble? Theoretically, someone could craft a perfect phishing attack, but who would go to all that trouble? Spray-and-pray, low precision, high surface area, attacks are the ones I end up reading about. The only reason this attack vector was open is because the red team stood to gain a massive benefit from succeeding in the attack. What real-world actor would go to the trouble and stand to benefit as much?
- lnsru 3mo agoImaginary country called Nicha can’t buy lithography machine from imaginary company called SAML. Nicha can kidnap some scientists and torture them to get all the secrets. But it’s not elegant. Nicha can pay a lot for hacking and get the result in anonymous way. I guess 8 figures can be paid easily for these secrets. With that money “red team” can launch very nice multifaceted social hacking attack.
- Volundr 3mo ago> But who would go to all that trouble? I mean, a company I worked at had a significant amount of money stolen after the attackers spent 6 months sitting on their access waiting for the right moment to fake an (expected) reply to an email exchange. The original breach (or at least the breach of this executives account) involved a very targeted phish. When the potential payout is millions it justifies a lot of effort.
- lokar 3mo agoI remember at some point Google disallowed more phishing attacks from red teams. Nothing new was being learned. They always work.
- mannyv 3mo agoMaintenance employees are the weakest link. They aren't paid much and don't believe anything is important. Be nice to them and they'll be nice to you back.
- UnfitFootprint 3mo agoBeing overly suspicious of everyone is a terrible way to live. Maintenance should have the autonomy to do as they did here - and security correctly followed up. The right response should only be technical imo. A meeting room should not lead to this level of network access.
- Volundr 3mo ago> Maintenance should have the autonomy to do as they did Really? We're talking about letting strangers in through the literal back door.
- lokar 3mo agoA better approach is to train everyone to be polite and helpfully walk the person to reception, who can arrange access.
- UnfitFootprint 3mo agoYeah, true.
- handoflixue 3mo agoAgreed! As a friendly favor, could you please post your full name, ZIP code, credit card number, and the 3 digit security code on the back? - Love and peace, your neighbor on HackerNews (which is to say, I think you know that you can be friendly without being foolish - but if not I'm going to really enjoy the gift of that credit card :))
- bell-cot 3mo ago> There are a lot of lessons here, but they start with training every member of the team to be suspicious of people coming from the outside, without badges, no matter what they say or do. Schloss noted that, if someone looks and acts like they belong in a space, most people will treat them that way. > “First and foremost, what most people believe is crime is not crime. It's a Hollywood myth of what crime looks like,” Schloss told us. “I call it the ski mask bias. Everyone assumes you're not getting robbed until a person comes in with a ski mask and a gun yelling.” I call this "Trained By Hollywood Syndrome". It's a huge problem, and far beyond mere computer security.
- wseqyrku 3mo agoThis made my day for the third time today for every time I checked the homepage.
- uqual 3mo agoSince they came in through an open door, a fake badge that passed quick casual visual examination would have seemed potentially helpful here. I'm surprised the pen testers didn't craft such badges. Perhaps it was difficult to get a sufficiently high res image of a real badge from an employee entering or leaving the facility (although, if the front desk is manned, it might be possible to walk up to the desk with an innocuous question and snap a pic of the receptionist's badge if it's visible)? I've never worked anywhere that stressed keeping your badge concealed until the moment of entry and concealing it upon last "scan" point on exit. If followed, such a policy would slightly reduce the risk of fake, but visually adequate, badges -- but compliance with such a policy would probably be very low in most commercial situations.