<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: krebsonsecurity</title><link>https://news.ycombinator.com/user?id=krebsonsecurity</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 01 Aug 2026 01:10:04 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=krebsonsecurity" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by krebsonsecurity in "Read this before you buy that TV streaming stick"]]></title><description><![CDATA[
<p>It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy software, among other malicious apps. They currently track almost 1,000 different makes and model numbers.<p><a href="https://github.com/synthient/public-research/blob/main/2026/01/kimwolf/product_names.csv" rel="nofollow">https://github.com/synthient/public-research/blob/main/2026/...</a></p>
]]></description><pubDate>Thu, 30 Jul 2026 17:32:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=49113084</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=49113084</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49113084</guid></item><item><title><![CDATA[Who runs the ransomware group 'The Gentlemen?']]></title><description><![CDATA[
<p>Article URL: <a href="https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/">https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48482503">https://news.ycombinator.com/item?id=48482503</a></p>
<p>Points: 15</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 10 Jun 2026 20:49:49 +0000</pubDate><link>https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=48482503</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48482503</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Children with cancer scammed out of millions fundraised for their treatment"]]></title><description><![CDATA[
<p>Sometimes just a little bit DNS research can yield a lot of useful results.<p>Looking at the passive DNS records for the domain chanceletikva.org shows it references the email address davidm@yeahdim.co.il.That email address is tied to multiple website registrations for a person by the name of David Margaliot, and also Shoshana Margaliot.<p>A search on this name in Domaintools finds the name David Margaliot tied to at least 25 domains, including ezri.org.il, which is a very odd site that features a huge image of a young child who is apparently in the hospital holding a gift wrapped box with a teddy bear. The site asks for donations but has a strange mission statement: Ezri Association promotes life-saving innovation through a surveillance drone project for emergency response teams, the establishment of an international medical knowledge database, along with other technological initiatives".<p>I'll probably continue the rest of this in a follow-up story.</p>
]]></description><pubDate>Tue, 16 Dec 2025 16:32:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=46290618</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=46290618</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46290618</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Attackers can decloak routing-based VPNs"]]></title><description><![CDATA[
<p>I interviewed some smart people about their research in story published today:<p><a href="https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-as-secure-as-it-claims/" rel="nofollow">https://krebsonsecurity.com/2024/05/why-your-vpn-may-not-be-...</a></p>
]]></description><pubDate>Mon, 06 May 2024 21:56:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=40279971</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=40279971</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40279971</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Twitter's pivot to x.com is a gift to phishers"]]></title><description><![CDATA[
<p>Thanks. I did update the story to reflect the apparent fix. I'm still trying to verify if this behavior remains in some form.</p>
]]></description><pubDate>Wed, 10 Apr 2024 15:15:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=39991668</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=39991668</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39991668</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "You can't leak users' data if you don't hold it"]]></title><description><![CDATA[
<p>This is the way. You don't have to protect what you don't collect. Mullvad is an excellent example of this. They don't even want you to pick a password, and they're fine if you just mail them cash as payment.</p>
]]></description><pubDate>Fri, 29 Mar 2024 01:23:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=39859548</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=39859548</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39859548</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Mozilla Drops Onerep After CEO Admits to Running People-Search Networks"]]></title><description><![CDATA[
<p>Their earlier statement said they were aware of the CEO's history but were assured that part of his life was behind him. From that statement on March 15: “We were aware of the past affiliations with the entities named in the article and were assured they had ended prior to our work together,” the statement reads. “We’re now looking into this further. We will always put the privacy and security of our customers first and will provide updates as needed.”<p><a href="https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-company-onerep-com-founded-dozens-of-people-search-firms/#more-66752" rel="nofollow">https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-comp...</a></p>
]]></description><pubDate>Sat, 23 Mar 2024 13:25:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=39799769</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=39799769</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39799769</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Optery's Statement Following Investigative Report on Onerep by Krebs on Security"]]></title><description><![CDATA[
<p>It's good to see others coming forward with what they know.<p>Previous discussion on this here: <a href="https://news.ycombinator.com/item?id=39709089">https://news.ycombinator.com/item?id=39709089</a><p>Original story: <a href="https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-company-onerep-com-founded-dozens-of-people-search-firms/" rel="nofollow">https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-comp...</a></p>
]]></description><pubDate>Mon, 18 Mar 2024 16:58:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=39746937</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=39746937</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39746937</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "U.S. Internet leaked years of internal, customer emails"]]></title><description><![CDATA[
<p>Possibly useful info: A list of customer domains affected.<p><a href="https://docs.google.com/spreadsheets/d/1wgKe1VrfNF8Afav1aJtMrZDeNuqBtSFku58fWlCBp6Q/edit?usp=sharing" rel="nofollow">https://docs.google.com/spreadsheets/d/1wgKe1VrfNF8Afav1aJtM...</a><p>One caveat: This list should not be considered exhaustive or complete by any means. e.g. changing the URL slightly by incrementing or decrementing a number in the URL caused a slightly different set of customers to be listed. I didn’t have a chance to go through it all before they took it down (note to self: pillage BEFORE burning).</p>
]]></description><pubDate>Wed, 14 Feb 2024 20:05:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=39374534</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=39374534</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39374534</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Fla. Man Charged in SIM-Swapping Spree Is Key Suspect in Hacker Groups Oktapus"]]></title><description><![CDATA[
<p>The identity of the defendant has been doing this for many years and is one of the original members of the Com. The people in that scene sim-swapping artists for their music are those that have already made their stolen millions, and have  long ago graduated from stealing usernames and gamertag handles.</p>
]]></description><pubDate>Fri, 02 Feb 2024 15:03:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=39229362</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=39229362</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39229362</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "It's still easy for anyone to become you at Experian"]]></title><description><![CDATA[
<p><a href="https://www.ftc.gov/legal-library/browse/statutes/fair-credit-reporting-act" rel="nofollow noreferrer">https://www.ftc.gov/legal-library/browse/statutes/fair-credi...</a><p>IANAL either, but it seems the losses suffered from ID fraud are only recoverable via this.</p>
]]></description><pubDate>Sun, 12 Nov 2023 04:10:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=38237214</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=38237214</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38237214</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Who's behind the SWAT USA reshipping service?"]]></title><description><![CDATA[
<p>Some of the exposure in these cases is due to the fact that you have cybercriminals who've been doing the same things for more than a decade. That is a very long time in which to make just a few key opsec mistakes, and also most RU cybercriminals back then did not take as much care to cover their tracks as they do today.</p>
]]></description><pubDate>Mon, 06 Nov 2023 15:53:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=38164202</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=38164202</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38164202</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "The fake browser update scam gets a makeover"]]></title><description><![CDATA[
<p>Not sure if it's exactly the same thing as what you just mentioned, but I did write recently about criminals using paid Google ads to get their links for popular software downloads show up before even the first organic search result. And it includes the right icons and branding, and people click and are brought to a site that looks an awful lot like a site Microsoft might use to let you download Teams, and you get an information stealer program instead.<p>Tl;dr, there are multiple ransomware groups that are using this method to find new infostealer victims.<p><a href="https://krebsonsecurity.com/2023/09/snatch-ransom-group-exposes-visitor-ip-addresses/" rel="nofollow noreferrer">https://krebsonsecurity.com/2023/09/snatch-ransom-group-expo...</a></p>
]]></description><pubDate>Wed, 18 Oct 2023 19:17:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=37933393</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=37933393</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37933393</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Experts fear crooks are cracking keys stolen in LastPass breach"]]></title><description><![CDATA[
<p>I thought about that also, and then one of the victims I talked to brought up a good point. An 8 character password with symbols and numbers doesn't sound like a great password today, but many of the accounts getting drained were tied to people who were very early LastPass users, and mostly longtime investors. Back then, affordable GPUs that can do 4 million hash cracking attempts per second weren't really a thing.<p>What I found was a lot of people made security assumptions and never revisited those assumptions. Or never fully did.</p>
]]></description><pubDate>Wed, 06 Sep 2023 01:08:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=37400108</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=37400108</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37400108</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Service Rents Email Addresses for Account Signups"]]></title><description><![CDATA[
<p>This is a fair assumption, although to be fair a botnet is essentially a collection of residential proxies.<p>And yes, Kopeechka controls the inbox, and only lets you see stuff going forward that matches the regex you specify.</p>
]]></description><pubDate>Wed, 07 Jun 2023 14:25:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=36227172</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=36227172</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36227172</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Service Rents Email Addresses for Account Signups"]]></title><description><![CDATA[
<p>Thank you for the reminder that I meant to add some of that context in the story (which I will do after finishing this comment). I've written several stories over the years about how the major email providers have erected various hurdles designed to increase the costs for spammers, most notably phone verification. However, much of the data I'm aware of on the topic of pricing is somewhat dated. Here's one study from 2011, which found Hotmail accounts were far cheaper than Gmail and others because they were basically way easier to register.<p>Accounts Craigslist PVA 10 (4) $4.25
[§B.1] Gmail Accounts 6 (5) $0.07
Hotmail Accounts* 21 (12) $0.007
Facebook Accounts* 24 (10) $0.07<p>I doubt these prices are relevant today, apart from the continued price disparity between email providers.<p>Source:<p><a href="https://krebsonsecurity.com/wp-content/uploads/2011/07/sec11-final186.pdf" rel="nofollow">https://krebsonsecurity.com/wp-content/uploads/2011/07/sec11...</a></p>
]]></description><pubDate>Wed, 07 Jun 2023 14:20:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=36227125</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=36227125</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36227125</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)"]]></title><description><![CDATA[
<p>This appears to be related. One Github user shared an alert they got today, two days after connecting their Github account to Gitlab. Something about an app added to the account. Their Github has 2fa turned on and a very strong password:<p><a href="https://twitter.com/briankrebs/status/1509910113716514822" rel="nofollow">https://twitter.com/briankrebs/status/1509910113716514822</a></p>
]]></description><pubDate>Fri, 01 Apr 2022 15:36:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=30879261</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=30879261</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30879261</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "Ask HN: How did my LastPass master password get leaked?"]]></title><description><![CDATA[
<p>The location supplied by the LastPass notification for these login attempt IPs seems off. E.g., just taking some of the IPs most frequently posted here as sources of master password login attempts:<p>196.19.204.79 Stated location: India 
WHOIS: Poland Warszawa Unit 117, Seychelles (Legacy) AFRINIC AS202769 COOP, US<p>160.116.206.37 Stated location: Germany 
WHOIS: Affiliated Computing Services, South Africa AFRINIC AS262287 Maxihost LTD, BR<p>168.81.122.153 Stated location: Germany 
WHOIS: Seychelles AFRINIC 202769 COOP, US<p>Someone is probably putting bogus information into the routes for these IP ranges. But what do all of these IPs have in common? According to my records, they are all related to a dodgy hosting provider in the Netherlands called Ecatel, now called Qasi Networks or IP Volume. And this is all disputed AFRINIC IP space, as per:<p><a href="https://krebsonsecurity.com/2019/12/the-great-50m-african-ip-address-heist/" rel="nofollow">https://krebsonsecurity.com/2019/12/the-great-50m-african-ip...</a></p>
]]></description><pubDate>Tue, 28 Dec 2021 20:27:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=29717675</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=29717675</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29717675</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "NY Man Pleads Guilty in $20M SIM Swap Theft"]]></title><description><![CDATA[
<p>That's nice to hear. So the SIM swappers have to double their bribes.<p>I think the best solution is to cut the mobile providers out of the equation altogether. I've long advised removing your phone number from anything you can, or at least substituting a voip service that can't be social engineered over the phone. Some services don't let you use voip services for multi-factor or signup, so your mileage may vary.<p>Also, it's important where possible to use types of multi-factor that don't rely on your phone number. The tricky part is, so many sites will let you reset your password if you can receive a link via SMS at the phone number on file for the account. Which means anyone who SIM-swaps you then can reset the passwords on those accounts that allow SMS resets (which is a lot, still).</p>
]]></description><pubDate>Thu, 16 Dec 2021 18:40:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=29582014</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=29582014</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29582014</guid></item><item><title><![CDATA[New comment by krebsonsecurity in "The ‘Zelle fraud’ scam: how it works, how to fight back"]]></title><description><![CDATA[
<p>I agree with your point about not acknowledging these scam attempts. Just wanted to point out the "fight back" bit of the story was advice for people who've already been victimized and are being told their bank won't cover the loss.</p>
]]></description><pubDate>Sat, 20 Nov 2021 01:08:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=29284638</link><dc:creator>krebsonsecurity</dc:creator><comments>https://news.ycombinator.com/item?id=29284638</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29284638</guid></item></channel></rss>