HNHacker News
TopNewBestAskShowJobs

krebsonsecurity

272 karma · joined March 9, 2019

submissionscomments
krebsonsecurity··on FBI Probes Service Selling 153M+ Drivers Licenses
Deleting the data after verification is a good practice. But if you're actively compromised, it probably doesn't matter how long you keep the data because it's already been immediately "backed up" by the intruders the second it is collected.

Much like Target and Home Depot with their big credit card breaches a decade ago. Everyone was up in arms about these companies "storing" full credit card records, when in reality the attackers had card-sniffing malware installed on every single cash register at every single store across the country.

krebsonsecurity··on Read this before you buy that TV streaming stick
It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy software, among other malicious apps. They currently track almost 1,000 different makes and model numbers.

https://github.com/synthient/public-research/blob/main/2026/...

krebsonsecurity··on Children with cancer scammed out of millions fundraised for their treatment
Sometimes just a little bit DNS research can yield a lot of useful results.

Looking at the passive DNS records for the domain chanceletikva.org shows it references the email address davidm@yeahdim.co.il.That email address is tied to multiple website registrations for a person by the name of David Margaliot, and also Shoshana Margaliot.

A search on this name in Domaintools finds the name David Margaliot tied to at least 25 domains, including ezri.org.il, which is a very odd site that features a huge image of a young child who is apparently in the hospital holding a gift wrapped box with a teddy bear. The site asks for donations but has a strange mission statement: Ezri Association promotes life-saving innovation through a surveillance drone project for emergency response teams, the establishment of an international medical knowledge database, along with other technological initiatives".

I'll probably continue the rest of this in a follow-up story.

krebsonsecurity··on Attackers can decloak routing-based VPNs
I interviewed some smart people about their research in story published today:

https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-...

krebsonsecurity··on Twitter's pivot to x.com is a gift to phishers
Thanks. I did update the story to reflect the apparent fix. I'm still trying to verify if this behavior remains in some form.
krebsonsecurity··on You can't leak users' data if you don't hold it
This is the way. You don't have to protect what you don't collect. Mullvad is an excellent example of this. They don't even want you to pick a password, and they're fine if you just mail them cash as payment.
krebsonsecurity··on Mozilla Drops Onerep After CEO Admits to Running People-Search Networks
Their earlier statement said they were aware of the CEO's history but were assured that part of his life was behind him. From that statement on March 15: “We were aware of the past affiliations with the entities named in the article and were assured they had ended prior to our work together,” the statement reads. “We’re now looking into this further. We will always put the privacy and security of our customers first and will provide updates as needed.”

https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-comp...

krebsonsecurity··on Optery's Statement Following Investigative Report on Onerep by Krebs on Security
It's good to see others coming forward with what they know.

Previous discussion on this here: https://news.ycombinator.com/item?id=39709089

Original story: https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-comp...

krebsonsecurity··on U.S. Internet leaked years of internal, customer emails
Possibly useful info: A list of customer domains affected.

https://docs.google.com/spreadsheets/d/1wgKe1VrfNF8Afav1aJtM...

One caveat: This list should not be considered exhaustive or complete by any means. e.g. changing the URL slightly by incrementing or decrementing a number in the URL caused a slightly different set of customers to be listed. I didn’t have a chance to go through it all before they took it down (note to self: pillage BEFORE burning).

krebsonsecurity··on Fla. Man Charged in SIM-Swapping Spree Is Key Suspect in Hacker Groups Oktapus
The identity of the defendant has been doing this for many years and is one of the original members of the Com. The people in that scene sim-swapping artists for their music are those that have already made their stolen millions, and have long ago graduated from stealing usernames and gamertag handles.
krebsonsecurity··on It's still easy for anyone to become you at Experian
https://www.ftc.gov/legal-library/browse/statutes/fair-credi...

IANAL either, but it seems the losses suffered from ID fraud are only recoverable via this.

krebsonsecurity··on Who's behind the SWAT USA reshipping service?
Some of the exposure in these cases is due to the fact that you have cybercriminals who've been doing the same things for more than a decade. That is a very long time in which to make just a few key opsec mistakes, and also most RU cybercriminals back then did not take as much care to cover their tracks as they do today.
krebsonsecurity··on The fake browser update scam gets a makeover
Not sure if it's exactly the same thing as what you just mentioned, but I did write recently about criminals using paid Google ads to get their links for popular software downloads show up before even the first organic search result. And it includes the right icons and branding, and people click and are brought to a site that looks an awful lot like a site Microsoft might use to let you download Teams, and you get an information stealer program instead.

Tl;dr, there are multiple ransomware groups that are using this method to find new infostealer victims.

https://krebsonsecurity.com/2023/09/snatch-ransom-group-expo...

krebsonsecurity··on Experts fear crooks are cracking keys stolen in LastPass breach
I thought about that also, and then one of the victims I talked to brought up a good point. An 8 character password with symbols and numbers doesn't sound like a great password today, but many of the accounts getting drained were tied to people who were very early LastPass users, and mostly longtime investors. Back then, affordable GPUs that can do 4 million hash cracking attempts per second weren't really a thing.

What I found was a lot of people made security assumptions and never revisited those assumptions. Or never fully did.

krebsonsecurity··on Service Rents Email Addresses for Account Signups
This is a fair assumption, although to be fair a botnet is essentially a collection of residential proxies.

And yes, Kopeechka controls the inbox, and only lets you see stuff going forward that matches the regex you specify.

krebsonsecurity··on Service Rents Email Addresses for Account Signups
Thank you for the reminder that I meant to add some of that context in the story (which I will do after finishing this comment). I've written several stories over the years about how the major email providers have erected various hurdles designed to increase the costs for spammers, most notably phone verification. However, much of the data I'm aware of on the topic of pricing is somewhat dated. Here's one study from 2011, which found Hotmail accounts were far cheaper than Gmail and others because they were basically way easier to register.

Accounts Craigslist PVA 10 (4) $4.25 [§B.1] Gmail Accounts 6 (5) $0.07 Hotmail Accounts* 21 (12) $0.007 Facebook Accounts* 24 (10) $0.07

I doubt these prices are relevant today, apart from the continued price disparity between email providers.

Source:

https://krebsonsecurity.com/wp-content/uploads/2011/07/sec11...

krebsonsecurity··on Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)
This appears to be related. One Github user shared an alert they got today, two days after connecting their Github account to Gitlab. Something about an app added to the account. Their Github has 2fa turned on and a very strong password:

https://twitter.com/briankrebs/status/1509910113716514822

krebsonsecurity··on Ask HN: How did my LastPass master password get leaked?
The location supplied by the LastPass notification for these login attempt IPs seems off. E.g., just taking some of the IPs most frequently posted here as sources of master password login attempts:

196.19.204.79 Stated location: India WHOIS: Poland Warszawa Unit 117, Seychelles (Legacy) AFRINIC AS202769 COOP, US

160.116.206.37 Stated location: Germany WHOIS: Affiliated Computing Services, South Africa AFRINIC AS262287 Maxihost LTD, BR

168.81.122.153 Stated location: Germany WHOIS: Seychelles AFRINIC 202769 COOP, US

Someone is probably putting bogus information into the routes for these IP ranges. But what do all of these IPs have in common? According to my records, they are all related to a dodgy hosting provider in the Netherlands called Ecatel, now called Qasi Networks or IP Volume. And this is all disputed AFRINIC IP space, as per:

https://krebsonsecurity.com/2019/12/the-great-50m-african-ip...

krebsonsecurity··on NY Man Pleads Guilty in $20M SIM Swap Theft
That's nice to hear. So the SIM swappers have to double their bribes.

I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary.

Also, it's important where possible to use types of multi-factor that don't rely on your phone number. The tricky part is, so many sites will let you reset your password if you can receive a link via SMS at the phone number on file for the account. Which means anyone who SIM-swaps you then can reset the passwords on those accounts that allow SMS resets (which is a lot, still).

krebsonsecurity··on The ‘Zelle fraud’ scam: how it works, how to fight back
I agree with your point about not acknowledging these scam attempts. Just wanted to point out the "fight back" bit of the story was advice for people who've already been victimized and are being told their bank won't cover the loss.
krebsonsecurity··on Cloudflare blocks an almost 2 Tbps multi-vector DDoS attack
CF: Would it be asking too much to have a date and time stamp on your blog posts somewhere?
krebsonsecurity··on Man Robbed of 16 Bitcoin Sues Young Thieves’ Parents
Yep. And it was worth close to a million on the day he filed this lawsuit.
krebsonsecurity··on Serial swatter who caused death gets five years in prison
There's no probation in the federal system. He will serve the 60 months.
krebsonsecurity··on Using fake reviews to find dangerous extensions
You are correct. Using the "forgot your password" function on Gmail often reveals snippets of the email account used for recovery and authentication of that account.
krebsonsecurity··on Try This One Weird Trick Russian Hackers Hate
Actually, yes the DarkSide ransomware has a Linux version. See: https://krebsonsecurity.com/wp-content/uploads/2021/05/darks...
krebsonsecurity··on 30k U.S. organizations newly hacked via holes in Microsoft Exchange Server
Yes, it was being used to target specific organizations prior to Microsoft's patches this week. Since then, attackers have basically used tools like Shodan to find unpatched servers, and mass-backdoored them -- regardless of who the victim organization is.
krebsonsecurity··on Killing TurboTax
Dare I add one other important story?

2 Former Employees Allege Intuit Made Millions Knowingly Processing Fake Refunds (Feb. 2015) https://news.ycombinator.com/item?id=9097974

krebsonsecurity··on Security Blueprints of Many Companies Leaked in Hack of Swedish Firm Gunnebo
I have no financial relationship to Hold Security. When Alex started his company, he asked if he could list me as an advisor. I said yes. I've never received any sort of remuneration for that role. If anything, he is more of an advisor to me, in terms of possible story tips.
krebsonsecurity··on The joys of owning an ‘OG’ email account
I actually wrote about that guy not long ago. His name is Mike O'Connor, and he owns bar.com, grill.com, place.com, and television.com, among others.

Probably his most famous domain was corp.com, which was recently bought by Microsoft because it turns out that older versions of Windows and other Microsoft products actually invited people to use corp.com for their internal Active Directory names. Problem is, when those machines are outside the internal network, they're constantly trying to share passwords and other sensitive data with corp.com.

More here:

https://krebsonsecurity.com/2020/02/dangerous-domain-corp-co...

https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-...

krebsonsecurity··on Confessions of an ID Theft Kingpin, Part II
The story was clear that this was only an estimate of damages. It also stated clearly that the investigators were somewhat constrained by the fact that Ngo's services did not keep reliable records of sales -- only what customers searched for.

I should add that in this case, a search for John Smith in Massachusetts would turn up all the John Smiths in Mass. The resulting sale (if there was one) could have been for all of the John Smiths in Mass, some of them, or just one. We don't know. This also made the notification of victims much more difficult.

Page 1 of 2Next →