HNHacker News
TopNewBestAskShowJobs

andrejodc

11 karma · joined November 18, 2018

submissionscomments
andrejodc··on The Loneliness Epidemic Is a Security Crisis
That's the point. You can't catch that immediately if you don't know what to look for. First the crypto part was mentioned much later. The profile was convincing. The woman said she is working as an illustrator and just mentioned that she does crypto in her free time. Also I know some friends who are also in the crypto space so it was for me not that unusual.
andrejodc··on The Loneliness Epidemic Is a Security Crisis
Recently I joined Tinder and Bumble and got more matches with scammers than with real people. I was not aware of pig butchering scams until I got curious about a young crypto-loving woman who helpfully taught me how buying and trading crypto works. Being inexperienced with crypto I just wanted to learn about the basics how to get started.

Long story short: After some time the woman suggested to try out some shady crypto trading website with a small amount which indeed made me about 50$ profit and everything could be successfully cashed out. In the next phase she asked me to repeat the same with at least 5k to make 100% profit.

Luckily all my alarm bells rang and I called it quits. However I can see how somebody less critical could fall for this. We need systems in place to prevent these schemes from succeeding.

andrejodc··on The situation at LastPass may be worse than they are letting on
It is highly unlikely that the attacker was able to crack the encryption. It's also highly unlikely that Lastpass had an unencrypted copy of the vault. However we know that all URLs are not encrypted which allows to identify users who have accounts for particular services e. g. cryptocurrency websites. The attacker could mount targeted attacks only on these lastpass users to reduce the risk of raising red flags. For example the attacker can send very convincing phishing mails to target these individuals with 0-day exploits. But an alternative much more scarier scenario could happen if the attacker found a way to extract the lastpass master password by injecting malicious code into the lastpass extension of targeted users. The possibility of this scenario depends if there is a way for lastpass servers to inject code into the browser extension.
andrejodc··on Improving Performance with Batching Client GraphQL Queries
The article completely misses the fact that every modern browser supports HTTP/2 which solves the problem of many concurrent HTTP requests. Moreover I don't like that the performance was measured with Chrome Dev Tools because I experienced significantly slower performance simply just by opening Dev Tools.