Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
krebsonsecurity
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
krebsonsecurity
15d ago
Deleting the data after verification is a good practice. But if you're actively compromised, it probably doesn't matter how long you keep the data because it's already been immediately "backed up" by the intruders t
2.
▲
by
krebsonsecurity
2mo ago
It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy soft
3.
▲
Who runs the ransomware group 'The Gentlemen?'
(krebsonsecurity.com)
15 points
by
krebsonsecurity
3mo ago
|
0 comments
4.
▲
by
krebsonsecurity
9mo ago
Sometimes just a little bit DNS research can yield a lot of useful results. Looking at the passive DNS records for the domain chanceletikva.org shows it references the email address davidm@yeahdim.co.il.That email address is tied to multipl
5.
▲
by
krebsonsecurity
2y ago
I interviewed some smart people about their research in story published today: https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-...
6.
▲
by
krebsonsecurity
2y ago
Thanks. I did update the story to reflect the apparent fix. I'm still trying to verify if this behavior remains in some form.
7.
▲
by
krebsonsecurity
2y ago
This is the way. You don't have to protect what you don't collect. Mullvad is an excellent example of this. They don't even want you to pick a password, and they're fine if you just mail them cash as payment.
8.
▲
by
krebsonsecurity
2y ago
Their earlier statement said they were aware of the CEO's history but were assured that part of his life was behind him. From that statement on March 15: “We were aware of the past affiliations with the entities named in the article an
9.
▲
by
krebsonsecurity
2y ago
It's good to see others coming forward with what they know. Previous discussion on this here: https://news.ycombinator.com/item?id=39709089 Original story: https://krebsonsecurity.com/2024/03/
10.
▲
by
krebsonsecurity
3y ago
Possibly useful info: A list of customer domains affected. https://docs.google.com/spreadsheets/d/1wgKe1VrfNF8Afav1aJtM... One caveat: This list should not be considered exhaustive or complete by any means. e.g. c
11.
▲
by
krebsonsecurity
3y ago
The identity of the defendant has been doing this for many years and is one of the original members of the Com. The people in that scene sim-swapping artists for their music are those that have already made their stolen millions, and have
12.
▲
by
krebsonsecurity
3y ago
https://www.ftc.gov/legal-library/browse/statutes/fair-credi... IANAL either, but it seems the losses suffered from ID fraud are only recoverable via this.
13.
▲
by
krebsonsecurity
3y ago
Some of the exposure in these cases is due to the fact that you have cybercriminals who've been doing the same things for more than a decade. That is a very long time in which to make just a few key opsec mistakes, and also most RU cyb
14.
▲
by
krebsonsecurity
3y ago
Not sure if it's exactly the same thing as what you just mentioned, but I did write recently about criminals using paid Google ads to get their links for popular software downloads show up before even the first organic search result. A
15.
▲
by
krebsonsecurity
3y ago
I thought about that also, and then one of the victims I talked to brought up a good point. An 8 character password with symbols and numbers doesn't sound like a great password today, but many of the accounts getting drained were tied
16.
▲
by
krebsonsecurity
3y ago
This is a fair assumption, although to be fair a botnet is essentially a collection of residential proxies. And yes, Kopeechka controls the inbox, and only lets you see stuff going forward that matches the regex you specify.
17.
▲
by
krebsonsecurity
3y ago
Thank you for the reminder that I meant to add some of that context in the story (which I will do after finishing this comment). I've written several stories over the years about how the major email providers have erected various hurdl
18.
▲
by
krebsonsecurity
4y ago
This appears to be related. One Github user shared an alert they got today, two days after connecting their Github account to Gitlab. Something about an app added to the account. Their Github has 2fa turned on and a very strong password: h
19.
▲
by
krebsonsecurity
5y ago
The location supplied by the LastPass notification for these login attempt IPs seems off. E.g., just taking some of the IPs most frequently posted here as sources of master password login attempts: 196.19.204.79 Stated location: India WHOI
20.
▲
by
krebsonsecurity
5y ago
That's nice to hear. So the SIM swappers have to double their bribes. I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or
21.
▲
by
krebsonsecurity
5y ago
I agree with your point about not acknowledging these scam attempts. Just wanted to point out the "fight back" bit of the story was advice for people who've already been victimized and are being told their bank won't cov
22.
▲
by
krebsonsecurity
5y ago
CF: Would it be asking too much to have a date and time stamp on your blog posts somewhere?
23.
▲
by
krebsonsecurity
5y ago
Yep. And it was worth close to a million on the day he filed this lawsuit.
24.
▲
by
krebsonsecurity
5y ago
There's no probation in the federal system. He will serve the 60 months.
25.
▲
by
krebsonsecurity
5y ago
You are correct. Using the "forgot your password" function on Gmail often reveals snippets of the email account used for recovery and authentication of that account.
26.
▲
by
krebsonsecurity
5y ago
Actually, yes the DarkSide ransomware has a Linux version. See: https://krebsonsecurity.com/wp-content/uploads/2021/05/darks...
27.
▲
by
krebsonsecurity
6y ago
Yes, it was being used to target specific organizations prior to Microsoft's patches this week. Since then, attackers have basically used tools like Shodan to find unpatched servers, and mass-backdoored them -- regardless of who the vi
28.
▲
by
krebsonsecurity
6y ago
Dare I add one other important story? 2 Former Employees Allege Intuit Made Millions Knowingly Processing Fake Refunds (Feb. 2015) https://news.ycombinator.com/item?id=9097974
29.
▲
by
krebsonsecurity
6y ago
I have no financial relationship to Hold Security. When Alex started his company, he asked if he could list me as an advisor. I said yes. I've never received any sort of remuneration for that role. If anything, he is more of an advisor
30.
▲
by
krebsonsecurity
6y ago
I actually wrote about that guy not long ago. His name is Mike O'Connor, and he owns bar.com, grill.com, place.com, and television.com, among others. Probably his most famous domain was corp.com, which was recently bought by Microsoft
More ›