Re: Urghhh So When Is Live 11 Coming?
Posted: Sat Feb 24, 2018 3:18 am
I can almost understand why some find it easier just to accept everything bad happens because Illuminati. Before long we'll all be begging for barcode tattoos or RFID chips just to make it stop.
For various reasons, I revisited my internet security recently, and I realised just how insecure everything is, and one of the weakest links was the lack of variety in my passwords. The University forces me to change theirs every few months, and no repetition is allowed, so it ends up being changed slightly, but more or less variations on a theme.
But one of the reasons was partly to do with reading up on, or watching videos about cyber security, and seeing just how easy it's getting to hack Wi-Fi. I even have a 4G wireless router, and live in a densely populated modern inner-city area.
Really, no matter how good these password systems are, you still need a password to log into them, and a password for your WiFi, and Internet Router, and so a man-in-the-middle type attack, or key-logger would make all of it pointless. In that respect a password manager is less secure. But I'm just getting too old and muddled to keep mental track of them all.
Just leaving your router at the default settings makes it surprisingly vulnerable, especially if it's one of the ones that defaults to the standard IP address with the default 'admin/admin' user/pass combo. Leaving Bluetooth on all the time also has its problems.
But with cellular networks involved, reading up on the SS7 flaw/exploit is an eye-opener. It's surprisingly easy for someone even a little techy to create a spoof phone tower and make your devices think they're logging into the real one. If they do that, they can access everything — calls, texts, basically anything you do or use the network for, and all networks still use SS7.
A guy at a hacker conference in 2014 showed how he'd kitted his Jeep out with a DIY "Stingray" type set up , basically like law enforcement use, that does something similar ("IMSI catchers"), for about $5k US, and he provided a PDF of instructions. Four years is a long time in technology, it's probably a lot cheaper and easier now even. Pretty sure a Raspberry Pi was part of it, and the most expensive components were single purpose things like signal amplifiers.
I think maybe all the NSA/Snowden stuff maybe got people thinking it's all about government spying, which can then maybe lead on to a kind of complacent "oh well, nothing i can really do about it, and I'm not very interesting and have nothing to hide" for most, but the far, far bigger problem is how accessible it's becoming for anyone else to get a hold of. And the thing with hackers is they don't necessarily hack you and immediately act on it, they might install something invisible and slowly collect data, then (for example) if you start visiting a lot of Bitcoin related sites, or doing something similarly interesting, you go up a notch on the automated list of potential targets.
Long story short, it's all so complicated and annoying, most of us pay nowhere near enough attention to this, and it's probably going to get a lot worse before we do.
For various reasons, I revisited my internet security recently, and I realised just how insecure everything is, and one of the weakest links was the lack of variety in my passwords. The University forces me to change theirs every few months, and no repetition is allowed, so it ends up being changed slightly, but more or less variations on a theme.
But one of the reasons was partly to do with reading up on, or watching videos about cyber security, and seeing just how easy it's getting to hack Wi-Fi. I even have a 4G wireless router, and live in a densely populated modern inner-city area.
Really, no matter how good these password systems are, you still need a password to log into them, and a password for your WiFi, and Internet Router, and so a man-in-the-middle type attack, or key-logger would make all of it pointless. In that respect a password manager is less secure. But I'm just getting too old and muddled to keep mental track of them all.
Just leaving your router at the default settings makes it surprisingly vulnerable, especially if it's one of the ones that defaults to the standard IP address with the default 'admin/admin' user/pass combo. Leaving Bluetooth on all the time also has its problems.
But with cellular networks involved, reading up on the SS7 flaw/exploit is an eye-opener. It's surprisingly easy for someone even a little techy to create a spoof phone tower and make your devices think they're logging into the real one. If they do that, they can access everything — calls, texts, basically anything you do or use the network for, and all networks still use SS7.
A guy at a hacker conference in 2014 showed how he'd kitted his Jeep out with a DIY "Stingray" type set up , basically like law enforcement use, that does something similar ("IMSI catchers"), for about $5k US, and he provided a PDF of instructions. Four years is a long time in technology, it's probably a lot cheaper and easier now even. Pretty sure a Raspberry Pi was part of it, and the most expensive components were single purpose things like signal amplifiers.
I think maybe all the NSA/Snowden stuff maybe got people thinking it's all about government spying, which can then maybe lead on to a kind of complacent "oh well, nothing i can really do about it, and I'm not very interesting and have nothing to hide" for most, but the far, far bigger problem is how accessible it's becoming for anyone else to get a hold of. And the thing with hackers is they don't necessarily hack you and immediately act on it, they might install something invisible and slowly collect data, then (for example) if you start visiting a lot of Bitcoin related sites, or doing something similarly interesting, you go up a notch on the automated list of potential targets.
Long story short, it's all so complicated and annoying, most of us pay nowhere near enough attention to this, and it's probably going to get a lot worse before we do.