1. Attachments are working again! Check out this thread for more details and to report any other bugs.

Google... Gmail hacked...

Discussion in 'Fred's House of Pancakes' started by amm0bob, Jun 1, 2011.

  1. amm0bob

    amm0bob Permanently Junior...

    Joined:
    May 29, 2008
    7,730
    2,547
    0
    Location:
    The last place on earth to get cable, Sacramento
    Vehicle:
    2008 Prius
    Model:
    II
  2. cwerdna

    cwerdna Senior Member

    Joined:
    Sep 4, 2005
    12,544
    2,123
    1
    Location:
    SF Bay Area, CA
    Vehicle:
    2006 Prius
    Here’s The Fake Gmail Site Chinese Hackers Used To Steal U.S., Activist Data - Andy Greenberg - The Firewall - Forbes has a comparison of a fake Gmail login page used for "spear phishing" vs. the real one. The differences are pretty subtle and I doubt I'd be able to spot anything amiss if it were presented to me, esp. given that there are subtle changes to Gmail all the time.

    I guess it's not that hard for a user to get confused by this (from contagio: Targeted attacks against personal accounts of military, government employees and associates):
     
  3. qbee42

    qbee42 My other car is a boat

    Joined:
    Mar 2, 2006
    18,058
    3,074
    7
    Location:
    Northern Michigan
    Vehicle:
    2006 Prius
    The key to avoiding this sort of trap is to never, ever log into any account from a link sent via email.

    For example, say that you get an email from your bank suggesting you need to verify your balance. Generally I would immediately delete this sort of message, but let's say we think it might be legitimate and we decide to check our bank account. Rather than click on the embedded link, close the email, open your browser, and manually navigate to the bank page.

    An embedded link might point to a false server, and sometimes they are very hard to spot. Navigating on your own or via your stored bookmarks is safe as long as the DNS is not compromised. If DNS gets compromised, all bets are off.

    Tom
     
    1 person likes this.
  4. Stev0

    Stev0 Honorary Hong Kong Cavalier

    Joined:
    Sep 23, 2006
    7,201
    1,073
    0
    Location:
    Northampton, MA
    Vehicle:
    2022 Prius Prime
    Model:
    Plug-in Base
    I pay almost all of my bills online, but I refuse to get my bills via email for this exact reason.
     
  5. cwerdna

    cwerdna Senior Member

    Joined:
    Sep 4, 2005
    12,544
    2,123
    1
    Location:
    SF Bay Area, CA
    Vehicle:
    2006 Prius
    Agreed but it seems they were receiving what looked like legit mail from someone they knew w/an attachment. When they tried to view or download the attachment, they got thrown to a fake Gmail login page instead of the normal behavior. I'm guessing they figured it was a Gmail glitch, so they happily entered their credentials.

    Yep, compromised DNS would be a very bad thing. It wouldn't surprise me if China has poisoned their DNSes too, given that they have the "great firewall".
     
  6. eagle33199

    eagle33199 Platinum Member

    Joined:
    Mar 2, 2006
    5,122
    268
    0
    Location:
    Minnesota
    Vehicle:
    2015 Prius v wagon
    Model:
    Two
    Sorry, personal peeve of mine... no one was hacked here, especially not google. In common usage, the term "hacked" indicates a severe breach of computer network security, often through the usage of exploits or vulnerabilities in code.

    This was a job of social engineering, where a fraudulent third party got users to willing give up their username and password. There was no hacking - just directing people to a website they thought was something else.
     
    1 person likes this.
  7. xpcman

    xpcman Senior Member

    Joined:
    Jun 11, 2009
    1,302
    295
    0
    Location:
    California - SF Bay area
    Vehicle:
    2008 Prius
    Why would "prominent" people be using Gmail anyway?
     
  8. amm0bob

    amm0bob Permanently Junior...

    Joined:
    May 29, 2008
    7,730
    2,547
    0
    Location:
    The last place on earth to get cable, Sacramento
    Vehicle:
    2008 Prius
    Model:
    II
    Gmail hackers had access for months - Technology & science - Security - msnbc.com

     
  9. amm0bob

    amm0bob Permanently Junior...

    Joined:
    May 29, 2008
    7,730
    2,547
    0
    Location:
    The last place on earth to get cable, Sacramento
    Vehicle:
    2008 Prius
    Model:
    II
    US probes Google's China hacking allegation - Technology & science - Security - msnbc.com

     
  10. amm0bob

    amm0bob Permanently Junior...

    Joined:
    May 29, 2008
    7,730
    2,547
    0
    Location:
    The last place on earth to get cable, Sacramento
    Vehicle:
    2008 Prius
    Model:
    II
    [ame=http://www.msnbc.msn.com/id/21134540/vp/43256544#43256544]msnbc.com Video Player[/ame]

    The SOS speaks about it...