Author Topic: The joys of internet use " Hackers "  (Read 2606 times)

0 Members and 1 Guest are viewing this topic.

Offline edz

  • Hard Top Camper User
  • ******
  • Posts: 6880
  • Thanked: 926 times
  • Gender: Male
  • " I dont like Sheeple "
The joys of internet use " Hackers "
« on: October 30, 2013, 12:26:24 PM »
Quite scary to think what can be done, bit of a read but eye opening .
http://pandodaily.com/2013/10/26/i-challenged-hackers-to-investigate-me-and-what-they-found-out-is-chilling/
" IMPROVISE  ADAPT   OVERCOME   and  PERSEVERE  "

Offline Bird

  • Once Was Lost, now am found
  • Hard Top Camper User
  • ******
  • Posts: I am a geek!!
  • Thanked: 1888 times
  • Gender: Male
  • Life is far too long....
    • My Place.
Re: The joys of internet use " Hackers "
« Reply #1 on: October 30, 2013, 01:21:01 PM »
Quite scary to think what can be done, bit of a read but eye opening .
http://pandodaily.com/2013/10/26/i-challenged-hackers-to-investigate-me-and-what-they-found-out-is-chilling/
Is this the same one

read the comments
http://www.theage.com.au/digital-life/consumer-security/what-hackers-can-discover-about-you-is-chilling-20131028-2wbec.html
-
Click to enlarge

Gone to a new home

Offline Beachman

  • Hard Top Camper User
  • ******
  • Posts: 1571
  • Thanked: 130 times
  • Gender: Male
Re: The joys of internet use " Hackers "
« Reply #2 on: October 30, 2013, 02:15:21 PM »
Very scary read

Offline kiva

  • Soft Floor Camper User
  • ****
  • Posts: 380
  • Thanked: 3 times
  • Gender: Male
Re: The joys of internet use " Hackers "
« Reply #3 on: October 30, 2013, 03:08:16 PM »
The password problem has been solved for many years.

Use a password manager and don't ever reuse passwords. Certainly don't use the same password on more than one website. If the website supports two-factor authentication then use it.

For questions that challenge things like "what is your mother's maiden name?", provide a random answer like ahfGwUvZmDllhaif, which is easily generated and stored within a password manager - there is no need to remember those random answers.

LandCruiser GXL 105 Series. Complete Campsite Exodus 14.

Offline bodgie

  • Tent User
  • ***
  • Posts: 127
  • Thanked: 1 times
Re: The joys of internet use " Hackers "
« Reply #4 on: November 01, 2013, 07:12:02 PM »
The password problem has been solved for many years.

Use a password manager and don't ever reuse passwords. Certainly don't use the same password on more than one website. If the website supports two-factor authentication then use it.


I'll disagree slightly with kiva, a password manager will make life much easier to manage different passwords across multiple site in a more secure manner, I'm not convinced it will solve the problem. The reason why I say this is the pen testers obtained access to the machine, once you have access you could then compromise the password manager database.

Often people will use the same password as their PC or Mac, if so you may be able to easily reverse the password hash used here which would then possibly allow the attacker to obtain access to your passwords.

For questions that challenge things like "what is your mother's maiden name?", provide a random answer like ahfGwUvZmDllhaif, which is easily generated and stored within a password manager - there is no need to remember those random answers.


This is good advice to follow as it makes it that little bit harder for an attacker. Often you'll get asked for your date of birth, my tip is don't provide your actual DOB, pick another date.

A number of websites will ask you to register before you can see some content. If you only want access to something simple, say download a PDF, try using a fake name and email address and see if this will let you download the file you want. If it wants to verify your address before you can download, you may then need to use your real address or you could use a crappy gmail or hotmail address just for these types of activities.

The good news about this paticular attack was it was harder for the pen testers to be able to retrieve the information and credentials they needed to make life interesting for the author.  The other interesting thing is they needed to try a number of different social engineering attacks to be able to get to this point, usually dropping a disk in an office will work in minutes.

While they needed to use social engineering attacks here it may not be necessary in all scenarios, remember they first were expecting to be able to use the authors home WiFi to compromise his computer.

I do information security for a living, we constantly hear the words, "I'm/we're not a target", "we have nothing of value". If you are a business and you have nothing of value, why do you exist? As an individual you have value to a criminal, the value you have is the money you may pay me if I make your life hard by encrypting your files.

Criminal activities like Ransomware (e.g. CryptoLocker http://en.wikipedia.org/wiki/CryptoLocker) are becoming more prevalent for the all users, I'd suggest you do some reading on how you can protect yourself.

FWIW, a firewall and virus software will not protect you against your own stupidity, don't open files from people you don't know.

The reality is you will have a problem one day, be prepared is my advice.

HTH,

Jason