STNSOLIDTECHNEWS
Software-SaaS •

Satisfy Ourmine, the ‘security’ Group Hacking Ceos and Celebs

By Enterprise Infrastructure Desk
9 min read
Satisfy Ourmine, the ‘security’ Group Hacking Ceos and Celebs
Consumer Protection & Privacy Complete Privacy & Compliance Kit ($15) Get all 3 statutory notices bundled (Data Erasure + Privacy Opt-Out + Credit Dispute Form).

Black hats hack for espionage, crime, and disruption. White hats hack to defend, digging up stability vulnerabilities so that they can be mounted. And then there are the puzzling types: hackers whose black hats are included in the thinnest coat of white paint, or so patchwork that even they do not appear to be to keep in mind which colour they’re sporting. Over the last pair of months a group calling by itself OurMine has proven by itself as distinguished customers of that third group. Late Sunday night time, the OurMine group claimed credit rating for compromising the Twitter and Quora accounts of Google CEO Sundar Pichai, posting messages looking through “hacked” and “we are just tests your security” to his fifty percent-million followers. Pichai is just the newest target of the group, which on Monday also hacked VC Mark Suster, and has now hit the Twitter accounts of Mark Zuckerberg, his sister Randi Zuckerberg, Spotify founder Daniel Ek, Amazon CTO Werner Vogels, and actor Channing Tatum. OurMine even goes so far as to brag about every single of individuals hacks on its site OurMine.org. And still on that very same internet site, it kinds by itself as a “Security Group,” offering personalized and company stability checks, with a $1,000 Paypal cost tag for a site scan, and $five,000 for a comprehensive enterprise audit. In a dialogue with WIRED, a single anonymous member of the group insisted that OurMine’s string of tech exec embarrassments is only its way of teaching us all a valuable lesson. “We do not want funds, but we are marketing stability providers simply because there is a large amount [of] people today [who] want to look at their stability,” he wrote in significantly less-than-great English, declining to give his identify or the site of what he described as OurMine’s 3-individual group. “We are not blackhat hackers, we are just a stability group…we are just attempting to explain to people today that nobody is protected.” The OurMine agent additional that the group hadn’t changed any of the passwords of the accounts it compromised—a well mannered contact it statements exhibits its benign intentions. But if their objective is to give stability warnings, why not privately tell the targets of their hacks of their vulnerabilities? “They will overlook us, so we really should show it,” the OurTeam spokesperson protests. “We didn’t do something completely wrong.” (He did be aware, having said that, that the group variations its IP addresses “every minute” to maintain in advance of regulation enforcement.) The anonymous member of OurMine says that the group was in a position to obtain regulate of Pichai’s Twitter feed via the CEO’s Quora account the two were being connected to permit quick tweeting of Quora posts. He then claimed that OurMine hacked Pichai’s Quora account utilizing a world-wide-web vulnerability that it’s given that claimed to Quora. But a Quora spokesperson says it has no history of any vulnerability report from OurMine, and that it’s “confident that Sundar Pichai’s account was not accessed by using a vulnerability in Quora’s methods.” Rather, the enterprise believes Pichai’s account was hacked owing to his reusing a password that was uncovered in a single of the several recent dumps of qualifications on the dark web—the very same trouble that led to Mark Zuckerberg’s Twitter account hack previously this month. As for OurMine’s other hacks, the group’s agent stated that it had hacked Amazon’s Werner Vogels and Randi Zuckerberg by exploiting a vulnerability in their Bit.ly accounts, which were being also connected to Twitter. But Bit.ly also denied in a statement to WIRED that the hacks had exploited vulnerabilities in its internet site, blaming compromised passwords. In simple fact, it’s value using all of OurMine’s statements with a heaping dose of skepticism. The OurMine member claimed, for instance, that the hackers have now collected $18,four hundred in service fees for stability providers they’ve carried out for prepared clientele. But when WIRED asked for evidence of individuals transactions, he sent a screenshot from the group’s PayPal account that appeared to be doctored: It showed $five,000 payments from the organizations Conversely and TruthFinder, but Conversely tells WIRED it under no circumstances paid for any this sort of “security” support. “The screenshot is fraudulent—we have under no circumstances listened to of OurMine right until now, and would definitely under no circumstances purchase this sort of a support,” Conversely spokesperson writes. TruthFinder didn’t straight away respond to a ask for for comment. All of that implies, if it weren’t now obvious, that individuals trying to get a stability audit really should almost certainly not engage a group of anonymous, lawbreaking Twitter-defacement artists. But OurMine does give some actual stability lessons, absolutely free of cost: Really do not reuse passwords in between web pages, set up two-aspect authentication, and be knowledgeable that linking accounts can direct to unanticipated stability threats. Your Twitter account, as OurMine has properly taught Sunder Pichai absolutely free of cost, is only as secure as the minimum-secure account that can article to it. Go Again to Top rated. Skip To: Start off of Posting.

Source url Share this:Click to share on Twitter (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on Google+ (Opens in new window)

Related

Black hats hack for espionage, crime, and disruption. White hats hack to defend, digging up stability vulnerabilities so that they can be mounted. And then there are the puzzling types: hackers whose black hats are included in the thinnest coat of white paint, or so patchwork that even they do not appear to be to keep in mind which colour they’re sporting.

Over the last pair of months a group calling by itself OurMine has proven by itself as distinguished customers of that third group. Late Sunday night time, the OurMine group claimed credit rating for compromising the Twitter and Quora accounts of Google CEO Sundar Pichai, posting messages looking through “hacked” and “we are just tests your security” to his fifty percent-million followers. Pichai is just the newest target of the group, which on Monday also hacked VC Mark Suster, and has now hit the Twitter accounts of Mark Zuckerberg, his sister Randi Zuckerberg, Spotify founder Daniel Ek, Amazon CTO Werner Vogels, and actor Channing Tatum.

OurMine even goes so far as to brag about every single of individuals hacks on its site OurMine.org. And still on that very same internet site, it kinds by itself as a “Security Group,” offering personalized and company stability checks, with a $1,000 Paypal cost tag for a site scan, and $five,000 for a comprehensive enterprise audit.

In a dialogue with WIRED, a single anonymous member of the group insisted that OurMine’s string of tech exec embarrassments is only its way of teaching us all a valuable lesson. “We do not want funds, but we are marketing stability providers simply because there is a large amount [of] people today [who] want to look at their stability,” he wrote in significantly less-than-great English, declining to give his identify or the site of what he described as OurMine’s 3-individual group. “We are not blackhat hackers, we are just a stability group…we are just attempting to explain to people today that nobody is protected.”

The OurMine agent additional that the group hadn’t changed any of the passwords of the accounts it compromised—a well mannered contact it statements exhibits its benign intentions. But if their objective is to give stability warnings, why not privately tell the targets of their hacks of their vulnerabilities? “They will overlook us, so we really should show it,” the OurTeam spokesperson protests. “We didn’t do something completely wrong.” (He did be aware, having said that, that the group variations its IP addresses “every minute” to maintain in advance of regulation enforcement.)

The anonymous member of OurMine says that the group was in a position to obtain regulate of Pichai’s Twitter feed via the CEO’s Quora account the two were being connected to permit quick tweeting of Quora posts. He then claimed that OurMine hacked Pichai’s Quora account utilizing a world-wide-web vulnerability that it’s given that claimed to Quora. But a Quora spokesperson says it has no history of any vulnerability report from OurMine, and that it’s “confident that Sundar Pichai’s account was not accessed by using a vulnerability in Quora’s methods.”

Rather, the enterprise believes Pichai’s account was hacked owing to his reusing a password that was uncovered in a single of the several recent dumps of qualifications on the dark web—the very same trouble that led to Mark Zuckerberg’s Twitter account hack previously this month. As for OurMine’s other hacks, the group’s agent stated that it had hacked Amazon’s Werner Vogels and Randi Zuckerberg by exploiting a vulnerability in their Bit.ly accounts, which were being also connected to Twitter. But Bit.ly also denied in a statement to WIRED that the hacks had exploited vulnerabilities in its internet site, blaming compromised passwords.

In simple fact, it’s value using all of OurMine’s statements with a heaping dose of skepticism. The OurMine member claimed, for instance, that the hackers have now collected $18,four hundred in service fees for stability providers they’ve carried out for prepared clientele. But when WIRED asked for evidence of individuals transactions, he sent a screenshot from the group’s PayPal account that appeared to be doctored: It showed $five,000 payments from the organizations Conversely and TruthFinder, but Conversely tells WIRED it under no circumstances paid for any this sort of “security” support. “The screenshot is fraudulent—we have under no circumstances listened to of OurMine right until now, and would definitely under no circumstances purchase this sort of a support,” Conversely spokesperson writes. TruthFinder didn’t straight away respond to a ask for for comment.

All of that implies, if it weren’t now obvious, that individuals trying to get a stability audit really should almost certainly not engage a group of anonymous, lawbreaking Twitter-defacement artists. But OurMine does give some actual stability lessons, absolutely free of cost: Really do not reuse passwords in between web pages, set up two-aspect authentication, and be knowledgeable that linking accounts can direct to unanticipated stability threats. Your Twitter account, as OurMine has properly taught Sunder Pichai absolutely free of cost, is only as secure as the minimum-secure account that can article to it.

Go Again to Top rated. Skip To: Start off of Posting.

Share this report:
Sponsored Advertisement