{"id":4128,"date":"2013-05-24T16:26:41","date_gmt":"2013-05-25T00:26:41","guid":{"rendered":"http:\/\/www.rifters.com\/crawl\/?p=4128"},"modified":"2013-05-24T16:26:41","modified_gmt":"2013-05-25T00:26:41","slug":"a-momentary-lapse-of-reason-an-appeal-to-the-hack-savvy","status":"publish","type":"post","link":"https:\/\/www.rifters.com\/crawl\/?p=4128","title":{"rendered":"A Momentary Lapse of Reason: An Appeal to the Hack-Savvy"},"content":{"rendered":"<p>My wife has just watched a big chunk of her life disappear: every e-mail or Gchat she ever sent or received since 2007.<\/p>\n<p>This is how it began:<\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/www.rifters.com\/crawl\/wp-content\/uploads\/2013\/05\/Phish.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter  wp-image-4131\" title=\"Phish\" src=\"http:\/\/www.rifters.com\/crawl\/wp-content\/uploads\/2013\/05\/Phish.jpg\" alt=\"\" width=\"559\" height=\"247\" srcset=\"https:\/\/www.rifters.com\/crawl\/wp-content\/uploads\/2013\/05\/Phish.jpg 699w, https:\/\/www.rifters.com\/crawl\/wp-content\/uploads\/2013\/05\/Phish-300x132.jpg 300w\" sizes=\"auto, (max-width: 559px) 100vw, 559px\" \/><\/a><\/p>\n<p>In a moment of dumbness, Caitlin clicked on the link: believe it or not, given the specific context of the missive it was actually plausible that it came from the person whose name was attached. Ever since then, everyone on Caitlin&#8217;s contact list has been getting the same message (some of us twice), this time signed &#8220;Caitlin&#8221;. And this is a savvy hack indeed: those suspicious enough to actually write back, asking if this was legit (the e-mail certainly lacked anything even close to the BUG&#8217;s narrative voice) received another e-mail in response, assuring them in the same fractured English that yes indeed, Caitlin was the actual author. At the same time the little fucker deletes your Gmail contact list; unless you have a photographic memory or an offsite record of your contacts, you lose the ability to send a mass warning to those on the hit list. The most you can do is wait until various perplexed and angry people write back, one by one, and reply to them in turn.<\/p>\n<p>Clever, then, but obvious phishery; I Googled a bit and learned that those who get suckered by this scam find themselves on a faux-Google page that tries to trick them into entering their Gmail login credentials. I also discovered that this agent doesn&#8217;t limit itself to e-mails; it&#8217;s starting to infiltrate <a href=\"http:\/\/thinkingsociology.wordpress.com\/2013\/05\/20\/you-have-a-new-google-doc-message\/\">blogs<\/a> and impersonate actual <a href=\"http:\/\/brianpinkowski.wordpress.com\/2013\/05\/24\/you-have-a-new-google-doc-message\/\">posts<\/a> (although even less convincingly in that context).<\/p>\n<p>Here&#8217;s the thing, though.\u00a0 While I&#8217;ve seen this fucker in action, and while I&#8217;ve found <a href=\"http:\/\/www.onlinethreatalerts.com\/article\/2013\/4\/25\/google-docs-phishing-email-scam\/\">alerts<\/a> at <a href=\"http:\/\/www.hoax-slayer.com\/google-docs-phishing-scam.shtml\">malware monitoring sites<\/a> and on\u00a0 <a href=\"http:\/\/productforums.google.com\/forum\/#!msg\/docs\/rMed--Q4noQ\/410VIOI0shUJ\">Google forums<\/a>, I haven&#8217;t found a single reference to its ability to wipe out the entire contents of one&#8217;s Gmail account. And that does seem to be the kind of thing that would warrant some sort of mention.<\/p>\n<p>Caitlin lost tens of thousands of cloud-borne e-mails. She never bothered to make local backups, trusting Google&#8217;s servers for such security\u2014 and while Google does apparently offer archiving services for <a href=\"http:\/\/www.google.com\/intx\/en\/enterprise\/apps\/business\/products.html?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=northam--2012q3--na_apps_smb_ha_2012-branded:70160000000jezbaag&amp;utm_term=%2Bgmail%20%2Barchiving#vault\">paying customers<\/a>, the most they do for us freeloaders is recommend that we keep local backups. (We will save for another time my rant about why you should never trust your data to the fucking cloud, and why certain authors who smugly proclaim &#8220;<a href=\"http:\/\/www.wired.com\/gadgetlab\/2012\/11\/ff-mat-honan-password-hacker\/all\/\">We are not going to retreat from the cloud<\/a>&#8221; either have their heads up their asses or are taking kickbacks from Google. Does anyone think the Cylons would have been able to pull it off if everyone on the Twelve Colonies had been running Xp?)<\/p>\n<p>Things have improved between this paragraph and the last. One of the BUG&#8217;s IT-savvy friends has come down to our booth (we&#8217;re drowning our sorrows at the Duke of Somerset) and discovered that her MacBook Air has, in fact, retained a scrambled and intermittent local backup of sorts. All is not lost, only some; and while the date-stamps on the remainder are totally fucked, the text of the surviving emails seems to be intact.<\/p>\n<p>Still. That was a fortuitous happenstance on a local flash drive. The definitive archive in the cloud is just <em>gone<\/em> \u2014 and from what we can tell, the surviving local subset will get nuked the moment we connect with that cloud. Something up there is still lurking in Caitlin&#8217;s account, hungry for kibbles and bits; it&#8217;s the Ebola of computer viruses, so virulent that it&#8217;s bound to implode from its own lethality before it has a chance to conquer the world.<\/p>\n<p>It&#8217;s conquered the BUG&#8217;s account, though. And the weird thing is, nobody else who&#8217;s reported this phish seems to have experienced anything remotely close to that level of lethality.<\/p>\n<p>I know you people, as a statistical population if not as individual faces. A lot of you eat bytes for breakfast.<\/p>\n<p>Any suggestions?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>My wife has just watched a big chunk of her life disappear: every e-mail or Gchat she ever sent or received since 2007. This is how it began: In a moment of dumbness, Caitlin clicked on the link: believe it or not, given the specific context of the missive it was actually plausible that it [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[],"class_list":["post-4128","post","type-post","status-publish","format-standard","hentry","category-misc"],"_links":{"self":[{"href":"https:\/\/www.rifters.com\/crawl\/index.php?rest_route=\/wp\/v2\/posts\/4128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rifters.com\/crawl\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rifters.com\/crawl\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rifters.com\/crawl\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rifters.com\/crawl\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4128"}],"version-history":[{"count":8,"href":"https:\/\/www.rifters.com\/crawl\/index.php?rest_route=\/wp\/v2\/posts\/4128\/revisions"}],"predecessor-version":[{"id":4137,"href":"https:\/\/www.rifters.com\/crawl\/index.php?rest_route=\/wp\/v2\/posts\/4128\/revisions\/4137"}],"wp:attachment":[{"href":"https:\/\/www.rifters.com\/crawl\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rifters.com\/crawl\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4128"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rifters.com\/crawl\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}