Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> With this level of trust it would be feasible to gain access to information protecting online accounts, a very scary thought.

Does he mean 'feasible to gain access to login information for online accounts'? I have read the page, and i'm not seeing it. Yes, according to the page they had access to some degree of personal information beyond the more publicly accessible. But that isn't the same as having access to their online accounts, or being near to getting it.



I meant that with that level of trust it wouldn't be too hard to adapt the attack to shift to gaining that sort of information. ie; We are adding you to our employee database but we need your SSN last 4.


My impression was that he meant that at that point it was potentially viable to scam some financial information out of the target.


"indormation protecting online accounts" makes me think of password reset questions.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: