Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How I would hack it (if I was evil and cared enough):

1. Gather info from whois DB, google search, site spidering, going to your house and looking through your trash.

2. Ring you up - Hello I'm Joe from the tax department/credit card company/bank we need to confirm your address .. give your address .. could I please confirm you are the credit card holder, I just need the last 4 digits

3. Ring your friends, family and business contacts - use smooth talking to gather as much info as possible.

4. Ring up Amazon - oh yes I am mister XXX, I forgot my password, please can you reset it. If they don't I'll try to guess information, and glean any info out of the replies.

5. Ring up your email provider and do the same

6. Keep on ringing about 8 hours apart to make sure I get different teams, so it's fresh each time, until I had enough info to get access to the account

7. Make sure to delete all backups

8. Deface to my hearts content - change all the passwords, blah blah

--------

This is the info I'd try and gather:

* Name - probably from whois

* DOB - probably from public records search - or ringing friends

* Phone - probably from your trash or mailbox

* Last four credit card digits - probably will get from your trash, or tricking you on the phone

* Date of last payment - Probably from tricking Amazon

* Password bits - pet's name, girfriend/wife/child names and ages, keylogger in an email I sent you



As always the weakest part of any security system is the people within it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: