I challenged hackers to investigate me (2013)(pando.com)
pando.com
I challenged hackers to investigate me (2013)
http://pando.com/2013/10/26/i-challenged-hackers-to-investigate-me-and-what-they-found-out-is-chilling/
36 comments
This is very true.
Just doing a reverse image search on google (with a photo of somebody) can result in finding all sorts of details. Once you have their facebook you have their name, with a name you can find their linkedin, from there its a wash. You can call past and present employers, locations, family, friends.
If somebody doesn't lock down their facebook page its even worse you can literally see all their photos.
Try googleing yourself and close friends, see how much you can learn without doing anything at all invasive or spending money. You'll quickly learn the importance of minimizing your online appearance after this.
Just doing a reverse image search on google (with a photo of somebody) can result in finding all sorts of details. Once you have their facebook you have their name, with a name you can find their linkedin, from there its a wash. You can call past and present employers, locations, family, friends.
If somebody doesn't lock down their facebook page its even worse you can literally see all their photos.
Try googleing yourself and close friends, see how much you can learn without doing anything at all invasive or spending money. You'll quickly learn the importance of minimizing your online appearance after this.
> If somebody doesn't lock down their facebook page its even worse you can literally see all their photos.
You can lock up your photos, but if your friends have public pictures with you, they can be found easily using the new graph search: "Photos of <name here>".
You can lock up your photos, but if your friends have public pictures with you, they can be found easily using the new graph search: "Photos of <name here>".
just FYI: gmail addresses ignore the '.', so [email protected] is the same as [email protected] and [email protected]
Right. And you can add "+whatever" to the end. But he mentions that the other person has a hyphen in their address.
More info from Google on "." and "+" at http://gmailblog.blogspot.com/2008/03/2-hidden-ways-to-get-m...
More info from Google on "." and "+" at http://gmailblog.blogspot.com/2008/03/2-hidden-ways-to-get-m...
It's easy to find a surprising amount out about people without even any 'hacker' skills.
It's the entire business model of Seisint (now owned by LexisNexis), ChoicePoint, and probably others.
We received some Seisint training. The idea was to use their service to uniquely identify patients, for electronic medical records. (The money people didn't pull the trigger, because they couldn't get the transaction cost low enough.)
My boss entered my name into the search field and says "Before I hit [Enter], is there anything you don't want me to know about? We don't have to do this."
Thank god I'm clean. It showed everything about me. Any public record any where was aggregated and collated. And showed it all in a nifty navigation hyper graph, linking me to every roommate, relative, job, residence, court document, etc.
It's the entire business model of Seisint (now owned by LexisNexis), ChoicePoint, and probably others.
We received some Seisint training. The idea was to use their service to uniquely identify patients, for electronic medical records. (The money people didn't pull the trigger, because they couldn't get the transaction cost low enough.)
My boss entered my name into the search field and says "Before I hit [Enter], is there anything you don't want me to know about? We don't have to do this."
Thank god I'm clean. It showed everything about me. Any public record any where was aggregated and collated. And showed it all in a nifty navigation hyper graph, linking me to every roommate, relative, job, residence, court document, etc.
> My boss entered my name into the search field and says "Before I hit [Enter], is there anything you don't want me to know about? We don't have to do this."
That's a bit weird, isn't it? Why did your boss enter your name, and not their own name? Or ask for a volunteer?
Granted, you were asked "should I go ahead or not", but you shouldn't have been forced into this situation in the first place. You could easily have had something in your history completely irrelevant to your work, but saying "don't" would reflect poorly on you regardless.
That's a bit weird, isn't it? Why did your boss enter your name, and not their own name? Or ask for a volunteer?
Granted, you were asked "should I go ahead or not", but you shouldn't have been forced into this situation in the first place. You could easily have had something in your history completely irrelevant to your work, but saying "don't" would reflect poorly on you regardless.
Yet look at all the trouble they went through. The vast majority of people who want to steal from you look for easy targets that involve far less work, like hacking Target. Sure it sounds scary but with even a little security effort you can make it not worth their while to attack you as an individual.
This is what I consistently tell people who won't back down from having so much of their personal stuff readily available on the internet. At the very least, make it somewhat difficult for people to connect the dots on your identity.
Exactly. It took several individuals two months to get into his files. I don't understand why number one on their list of attack vectors is physically breaking into his house. You're pen testing an individual and number one is B&E?
Why wouldn't it be? Physical access to a computer is the best way to own it.
I don't recall ever hearing about people lacking fingerprints. Here's an article about it: http://www.nytimes.com/2011/08/09/science/09obprint.html
Wide variety of skin issues will leave you with unstable, malformed, or even without fingerprints as well. Then you have a note in your passport that says that it doesn't contain that particular biodata.
Interesting comment. Thanks. My first thought is how that would be applied to Papers, Please.
That's probably what ultimately landed him a job at KPMG :)
"you won't believe what happens next"
I wrote a Java applet that will show you how to avoid some of these vulnerabilities. pm me for the link... ;-)
Genuine question : are JAR files sent as email attachments still the state-of-the-art in PC hijacking?
It was the tester's first time writing malware for a Mac - being able to target the JVM was probably just a simple way to re-use old code.
No, but the "user is ignorant" attack vector is still the most common. And for good reason.
Are there any services that will take my name, photos, and some personal info, and then shoot chaff across popular web services? Seems like enough bogus info would make it a lot harder to put together accurate information on someone.
[deleted]
* October 26, 2013
What's your point? It's possible to have an enriching conversation and/or discuss things that are more than a few hours old.
Sure, but it has been discussed before: https://news.ycombinator.com/item?id=6617497
Is your assertion that the maximum utility of an topic is realized on the first discussion?
Sure, so how often should content be recycled through HN?
Until people aren't interested in it any more.
If it's about the NSA or Bitcoin, everyday.
The site has a ranking system for posts that handle this question.
Totally.
However, in case said "things" are not from the current year, it is a habit on HN to include the date in the title — at least the year, like so:
I challenged hackers to investigate me and what they found out is chilling (2013)
Also, HN Search has just been drastically improved, so, when your "things" are not fresh from the morning, please use it to look for older submissions.
However, in case said "things" are not from the current year, it is a habit on HN to include the date in the title — at least the year, like so:
I challenged hackers to investigate me and what they found out is chilling (2013)
Also, HN Search has just been drastically improved, so, when your "things" are not fresh from the morning, please use it to look for older submissions.
Current HN search is fucking terrible, especially on mobile.
Can you tell us what's terrible? We are always eager to improve it.
sorry, it was just meant as indicator that it was not new. I read it back then so if I had known it was not a new story I would not have clicked. That's all. :)
A friend occasionally gets email for someone with his name that lives in a different country ([email protected] vs [email protected]). He told us this, plus the country and county the guy lived in, and asked a few geek friends of his what we could find out. He had withheld some info so he could verify our results.
Within a few minutes we had his address, his immigration status and photographs of his family. Which is quite scary.
(--edit-- this was using simple online tools like google and bing, plus government websites in the country concerned.)