Hackers Prove They Can ‘Pwn’ the Lives of Those Not Hyperconnected
bits.blogs.nytimes.com
bits.blogs.nytimes.com
This should be a wake up call to the have-nots: You aren't safe just because you don't post on Facebook and you don't use the computer. Just because you don't drive doesn't mean you can't be hit by a car.
If I have a vendata against you, I can break into your home and setup keyloggers, hidden video/audio recorders that "call home" or even allow me to "dial in" and listen in. I don't need your stinking post-it notes and I won't even have to be in a rush. (http://www.amazon.com/dp/B00CIXAF8O/ref=wl_it_dp_o_pC_S_ttl?...)
The only thing this pawnage verified for me is that there are a lot of people with malware running on their computers and these same people are susceptible to phishing scams.
They only got these after she let them into her house and gave them physical access to her computer. Of course it's only common sense that anyone that is allowed into your home and onto your computer can "pwn" you and worse - hacker or not. That's why 99.9% of people, including this woman, wouldn't allow strangers into their home and give them unfettered physical access to their computer.
The article title implies that they were able to "pwn" her through "hacking". The only mildly interesting they did in this regard was the spear-phishing attack based on her Facebook likes.
The underscore here is that a limited use case person, someone who occasionally posts limited things and doesn't do anything beyond casual ebaying can still be a victim.
The chain is only as strong as it's weakest link.
It is a useful article as a warning for non-technical people.
If you want to know more, I can recommend The Art of Deception by Kevin Mitnick.
She didn't need to though, they could have entered through the garage door while she was away.
To understand, that your door opener, your TV and other things can be "hacked" is important. The information to use different passwords for every service is important.
We as people in the know have to help our elders and peers to see how easy it is to use a pwd-mgr and have a little bit more basic security.
If nothing more, this piece goes a step in the right direction.
I'm not saying you should ditch password managers and just memorize all of your password. I'm just saying: use them as a well-informed user.
Back in the days, Bruce Schneier suggested to write passwords down on a piece of paper and keep it in your wallet as the least weak security measure. Today, based on this article[0], he actually recommends the use of a password manager "[...] simply because it allows you to choose longer and stronger passwords.", which basically means it's the lesser of two evils.
[0] https://www.schneier.com/blog/archives/2014/09/security_of_p...
I'm currently using PasswordSafe (in Wine on Linux) with git to version/synchronize between systems. It is kinda painful, but at least it's nice to not be syncing to somebody's cloud or running in a browser.
I've been thinking about converting an old Android device into a more secure password manager. I envision having the device hold the decryption key for the PW "vault" as long as it's connected to my authenticated system. I either request credentials from the PC and approve on-device, or select them on the screen, and it types them as a USB keyboard (or perhaps some other way less prone to garden-variety keyloggers.) I guess I haven't because it's kind of a lot of effort and will lower convenience levels. :)
I ought to at least find a better way than the clipboard, to transfer passwords from the manager app to the browser etc...
Edit: heh, that's funny, you edited your comment as I was replying? Now we just need someone to build it for us :)
When Bitcoin hardware wallets were first getting developed, I wondered why people didn't just start with open, barebones commodity hardware like you've described. Well, I suppose one reason may be that it may not exist, but it seems like it should be pretty cheap to pay some low-end Android manufacturer to remove a few features from their design. Or maybe you even buy "normal" hardware and strip out radios. At some level, the wallet manufacturers are all trusting someone, as I don't think any have designed their own low-level components. Anyway, maybe I will revisit that idea to see if a suitable locked-down, easy-to-hack, super-cheap device is available, as I agree that cutting all unnecessary comms is a good idea.
You're very very unlikely going to want to type a truly secure (= long) password over and over and over, which you'd need to do in a situation where the browser's password manager is turned off, and/or a website disables password caching anyway.
The Palm m5xx series could solve this problem: it had full USB, and I once read of an Palm app (like any other) that bridged the m5xx's SD slot to behave like a block device over USB, ie it turned the Palm into a USB SD card reader. That means there's a raw USB SDK out there, and adding HID keyboard support wouldn't be too hard (no kernel driver development etc).
Getting passwords into the device would be nontrivial; Palm keyboards are proprietary to the series they were made for, with a few arbitrary connector updates thrown in for good measure (think iPhone docking connector saga). If the password is irritating enough to repeatedly type on a full keyboard, it would take you a good 5 minutes (and a punching bag, for afterwards) to get it into the PDA, Graffiti and custom keyboards taken into account.
I think it would work out though: if the only way to get data out of the device is to tap something on its screen, that should be enough of a brick wall to dissuade would-be attackers.
I guess I'm responding to this so enthusiastically because it's about Palm :P - I unfortunately never owned one of these awesome little things, but I'd love something of similar capabilities built using today's tech. With modern advances in power consumption, like MemoryLCD, micropower CPUs, short-range bluetooth, etc, the result would probably last literally weeks. It'd be enormous fun to hack on, too, and carve out a little niche for itself. :)
I wonder if I should Ask HN if this would be a good idea.
I suppose if you can do full USB, you can probably get data in somehow.
Although... I just started thinking about the possibility of using a microcontroller that had a tiny bit of internal, non-reprogrammable ROM, so I could implement a secure stage-0 loader... lol
The firmware that's written to the chip is padded out to (sizeof(flash)-X) with cryptographicly secure random bytes, where X is the size of a crypto signature block, which you use to sign the firmware. When you plug the thing into a computer without the sd card inserted(I plan on storing the password vault on an sd card, correctly encrypted), it dumps all of the flash via keyboard. Pipe that into a program that verifies the signature, via whatever means, and you can ensure the firmware has not been tampered short of hardware modification in the form of adding more flash memory/eeprom, as to do so would require compressing the existing code/cryptgraphically secure padding, as you would need to dump the original out to pass the verification. If you want to be even more secure, you can even replace the existing signature with your own, therefore ensuring that people can't change the version without access to your private key.
In other news, I just placed an order for the parts for my prototype, so I'll be putting that together this weekend. Fun thing: If done correctly, it should work with most android phones, as they do understand usb hid keyboards. As a result, final design may end up with a very small lithium battery to allow it to run when connected to a phone that doesn't offer much power. I'll put a blog somewhere and post an update to https://twitter.com/andy_leap as I work on it.
3. Ask HN ask HN: Should I ask HN if a Palm Pilot keyboard would be a good password manager?
1 point by i336_ 1 minute ago | flag | past | web | discussAlso, to clarify - and I should've qualified what I meant, but tiredness is such an unhelpful thing at times - this is a genuinely interesting-sounding idea (as I noted to the other reply at this comment depth), but the paragraph at the bottom was kind of an independent thing.
I've always wanted to tinker around with a handheld, reasonably nice-looking device with similar specs to a Palm. Sort of like the TI watch (http://processors.wiki.ti.com/index.php/EZ430-Chronos), but a PDA equivalent.
With X selection buffers, when you're pasting data the X application you're pasting from gets to run arbitrary code (informed of the destination!) to determine what to send. I've been wanting a password manager that asks me for verification before transferring the data.
It matters with one goes faster: Cranking your PW manager or you typing in all your passwords.
They actually didn't even do the whole thing themselves. Instead hired a phishing service...
To me this is more similar to people dressed as UPS truck drivers going inside an apartment and stealing keys. Or a cashier taking a picture of a customer's credit card.
P.S. Excellent bot if it is a bot. It seems to be taking sides on an issue and not just summarizing, which I haven't seen happen previously with any other summary bots.
Social engineering is often a very efficient alternative to rainbow tables, wiretapping, buffer overruns and other technical exploits.
They didn't 'hire a phishing service'. They used a website.
Physically breaking in is a real threat. Now break-ins risk digital breaches as well as the old standards. Just because it involves being onsite doesn't mean it isn't a meaningful threat, and now it's not limited to just the artifacts that are stolen.
In fact, "standard" protocol in response to a physical home breakin should probably include a digital "audit."
I'm just disappointed that the article was about "hackers" but just talked about scams most of us are already aware of; seems kind of click-baity. They could have entitled the article "Here's One Easy Trick to Protect Yourself from Identity Theft."
be pretty cool if it was the former. that would be some serious natural language processing. (not that i know anything about that subject)
i read the article, this post does seem like a pretty accurate summary.
I'm surprised they only care about the electronic locks and didn't show how easy it is to pick most of the mechanical locks. Especially when they are talking about the "not hyperconnected" hacks.
Burglars have always targeted items that are valuable to them. Easy to sell, gets a good price, etc.
Now we have digital assets in the home, and burglars are going to focus on those things too. For most of the population, and probably many of "us", physical access to those digital assets isn't particularly secure. And to have those assets "taken" today is much more far reaching than to have lost a stereo or checkbook.
Just because the attacker had to get off his couch and go somewhere shouldn't minimize this threat. "Physical access means's you're pwned" is a true statement.
One thing I do at home, for example, is to use full disk encryption on my laptop, and hibernate it when I leave. So that if someone steals it, it's just a plastic brick. For exactly the scenario described in the article.
I'm signing up for Phish5. Looks like exactly what I need for my team.
For anybody who doubts that "gaining physical access" automatically disqualifies the results, let me share a recent uptick in a specific con in my area that could very well be adapted as a template to other unsuspecting areas:
Two men in hard-hats and workman clothes approach a home, clipboard in hand, and claim to be with the "power company" and want to have a moment of time to talk about some trees close to the power lines. It's a right of way issue. They ask for the resident to come out and take a look with them. All seems pretty normal.
The talker gets the person or couple's attention while the other makes a quick excuse to go back to the truck out in front of the house. The talker carries on about how they're going to take care of the trees at no cost to the residents, and they act very cordial overall. Meanwhile, the partner has gone into the home via the front door which was left unlocked, goes for the most likely targets of value (ex: jewelry). The partner goes to the truck while talker wraps up and leaves. By the time the residents notice anything is amiss, the duo are long gone.
Trust-cons are a huge issue for a large portion of the population, in my opinion. Being prepared to be charmed while being fleeced is not how normal people go about their day.
I don't claim to be hacking proof since I don't control every bit of my data myself, but if someone came into my house they wouldn't find passwords in a notebook or saved passwords in my browsers