Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Old Freeper Accounts Hijacked?
Original Content | 03/16/2025 | By Laz A. Mataz

Posted on 03/16/2025 6:09:41 AM PDT by Lazamataz

click here to read article


Navigation: use the links below to view more comments.
first previous 1-20 ... 281-300301-320321-340341-357 next last
To: Lazamataz

Getting closer.


321 posted on 03/16/2025 7:43:43 PM PDT by joesbucks
[ Post Reply | Private Reply | To 314 | View Replies]

To: Lazamataz

A post of beauty


322 posted on 03/16/2025 7:51:55 PM PDT by combat_boots
[ Post Reply | Private Reply | To 310 | View Replies]

To: Lazamataz

But, how do you REALLY feel?


323 posted on 03/16/2025 7:53:25 PM PDT by MayflowerMadam (It's hard not to celebrate the fall of bad people. - Bongino)
[ Post Reply | Private Reply | To 310 | View Replies]

To: Nik Naym

I miss how it used to show how many FReepers actually clicked on the thread, even without posting.


324 posted on 03/16/2025 7:54:02 PM PDT by Bikkuri (I am proud to be a PureBlood.)
[ Post Reply | Private Reply | To 93 | View Replies]

To: Chickensoup


"Tell me wasn’t there a visit counter to the threads back in the day???"


Lol.. I just mentioned that replying to another post!
Yeah, I used to pay attention to those to see if they were popular, or not.
325 posted on 03/16/2025 7:56:43 PM PDT by Bikkuri (I am proud to be a PureBlood.)
[ Post Reply | Private Reply | To 220 | View Replies]

To: Chickensoup

I think that was around the time when copy/pasted quotes would throw out some weird characters (wrong coding on the site, I think it was because not using UTF-8).
Took JohnRob a few weeks to fix.


326 posted on 03/16/2025 7:59:16 PM PDT by Bikkuri (I am proud to be a PureBlood.)
[ Post Reply | Private Reply | To 280 | View Replies]

To: DCPatriot

You can’t be series, this is HUGH!


327 posted on 03/16/2025 8:03:39 PM PDT by Bikkuri (I am proud to be a PureBlood.)
[ Post Reply | Private Reply | To 97 | View Replies]

To: redfreedom

I remember some trolls going back to the Palin election (I voted for her, not the canary).


328 posted on 03/16/2025 8:06:11 PM PDT by Bikkuri (I am proud to be a PureBlood.)
[ Post Reply | Private Reply | To 62 | View Replies]

To: bankwalker

Very good point.
Yeah, I dod remember it becoming very lax about that time.


329 posted on 03/16/2025 8:07:00 PM PDT by Bikkuri (I am proud to be a PureBlood.)
[ Post Reply | Private Reply | To 67 | View Replies]

To: Bikkuri

ROFL!


330 posted on 03/16/2025 8:10:58 PM PDT by DCPatriot ("It aint what you don't know that kills you. It's what you know that aint so" Theodore Sturgeon))
[ Post Reply | Private Reply | To 327 | View Replies]

To: buwaya

No, most of the foreign trolls were from loser countries like Spain and France.


331 posted on 03/16/2025 8:15:54 PM PDT by Bikkuri (I am proud to be a PureBlood.)
[ Post Reply | Private Reply | To 156 | View Replies]

To: Lazamataz

Laz is not being rude, funny, or insane. Expiring log-ins make sense. I now log in/ out every time i do a FReeper read session and erase my history because it is no one else in my family’s business what i do and say here. None of them agree with me now, and at least one would have malicious intent.


332 posted on 03/16/2025 9:51:33 PM PDT by drSteve78 ( Older Je suis Deplorable. Even more so)
[ Post Reply | Private Reply | To 16 | View Replies]

To: drSteve78

Oh no…are you living with some of the 29%?


333 posted on 03/16/2025 9:54:18 PM PDT by Allegra (🍈🍈🍈🍈🍈🍈🍈🍈🍈🍈🍈🍈🍈🍈🍈)
[ Post Reply | Private Reply | To 332 | View Replies]

To: palmer

An IMEI (International Mobile Equipment Identity) is a unique 15-digit code that identifies a mobile device, like a phone, similar to a VIN number on a car.

So 8n simple terms the MFA service generates an encrypted string from “FREEREPUBLIC-USERNAME-PASSWORD” and turns it into a QR code.

Nothing else knows how to decrypt the string, except that specific MFA app. If you use a photo app, QR scanner app, or Google Authenticator, they’ll throw an error because they can’t decrypt it.

When you scan the code, your phone adds its EMEI. So the MFA server receives “FREEREPUBLIC-USERNAME-PASSWORD-EMEI”.

Registration over.

From that point on, your username and password are tied to that specific app and the specific handset. A simple unlock challenge regenerates the encrypted string, ie “this is my username, this is my password, and I’m using THIS phone with THIS EMEI.”

If that matches what you registered, you’re logged in successfully.

If you lose your phone, you can go through the registration process again on the replacement phone, which can be done by emailing you a temporary code.


334 posted on 03/17/2025 12:57:00 AM PDT by MalPearce ("You see, but you do not observe" - Holmes to Watson, A Scandal in Bohemia)
[ Post Reply | Private Reply | To 248 | View Replies]

To: lightman

It is not hard to set up multiple options. Email, SMS, app, even an RSA or Yuibikey.

The whole point of all these mechanisms is to address the problem of password harvesting. ESPECIALLY for moderator/admin accounts.

Years ago I went into a datacenter and all the admin passwords were scribbled on the whiteboard. I could’ve run riot all through their network without them knowing it was me.

Imagine not having to go to the effort of taking a photo of a whiteboard because you can go on the dark web and get the photo from it...

Now imagine, everyone with zot abilities who has had the same password for fifteen years, has their login details in a freely available, hacked password list.

So even if MFA is overkill for Freepers, it should be mandatory for admins and moderators.


335 posted on 03/17/2025 1:08:03 AM PDT by MalPearce ("You see, but you do not observe" - Holmes to Watson, A Scandal in Bohemia)
[ Post Reply | Private Reply | To 320 | View Replies]

To: MalPearce

Admin/moderators vs. “ordinary” account holders is a very valid distinction.


336 posted on 03/17/2025 7:19:14 AM PDT by lightman (Beat the Philly fraud machine the Amish did onest, ja? Nein, zweimal they did already!)
[ Post Reply | Private Reply | To 335 | View Replies]

To: MalPearce
Thanks for the explanation. A couple questions

Does the MFA service use a secret key to encrypt the FR-USERNAME_PWD string and the app use the same secret key to decrypt it? If that's the case could the adversary reverse engineer the app to find the secret key? If so, could you deploy each MFA with a unique private key and register the public key at the server during the registration step? Seems like one of several ways to avoid the shared secret key problem.

Is the IMEI for my phone secret, or can it be looked up by an adversary pretending to be me? Serial number portion of the IMEI is six digits and the rest (manufacturer, model) would be publicly known. The six digits might become public through signaling or some other third party use of the number. The fact that you have the IMEI in your own server database is a red flag because it's no longer secret.

I suspect what you really need is a unique code on the device that is guaranteed to be secret. Simplest solution is a private key. When I did my bit of phone-based authenication I used the secure key storage in Android. In short the private key remains in the secure enclave and the only thing you can do with it as a programmer is use it to sign a message. I sign the message, send it to the server, the server validates the signature using the public key. The public key is stored in the server during the registration step (my registration was someone complex but still a separate step like you are doing).

337 posted on 03/17/2025 10:06:38 AM PDT by palmer (Democracy Dies Six Ways from Sunday)
[ Post Reply | Private Reply | To 334 | View Replies]

To: palmer

Depends on the service used. I currently have something like 40 services using Microsoft Authenticator with Entra ID, and 20 using Google. I also use Auth0, Cyberark, Nymi, Beyond Trust, and a few others.

The security is only as good as the security of the cloud platform. If someone can get onto the admin platform without MFA, all bets off.

Your EMEI is literally just a code representing the handset. This is why, professionally, I’d say NEVER lock MFA options down to MDM managed smartphones (the USA loves Apple MDM but you might as well advertise, “hack this one system and you’ve got the keys to the castle!”

If my employer got hacked they still wouldn’t be able to clone my MFA phone. It’s intentionally off grid. I’ve got the authenticators running in offline mode with the phone... Basically, it’s a 5 year old phone with no SIM and no WiFi, acting as a 60-in-one RSA token. It goes online only when I need to add another authenticator.

I used to use Myki password manager, which worked the same way. Passwords were stored in a TPM encrypted vault, private key known only to Myki. The sheer effort required to get into the vault (needed physical access to the phone with a way to bypass its biometric protection) combined with the fact nobody would know what passwords I had in there - made it borderline unhackable.


338 posted on 03/17/2025 10:36:55 AM PDT by MalPearce ("You see, but you do not observe" - Holmes to Watson, A Scandal in Bohemia)
[ Post Reply | Private Reply | To 337 | View Replies]

To: MalPearce
Ok, then that answers my questions. The only possibility of cloning would be SMS messaging where the user types or sends a message, mainly numeric, from the phone to the server.

MS Authenticator creates a private key for each registered service, associating whatever data is in the QR code sent by the service to that private key. Registration is essentially completed by sending the corresponding public key.

There's no IMEI involved, not needed and not useful. Private keys stored in the phone can't be extracted by any method. Once registered the service just has to validate a signed message using the public key. Cloning is impossible.

If there is an app of any sort on a phone it would use PKI.

339 posted on 03/17/2025 5:28:31 PM PDT by palmer (Democracy Dies Six Ways from Sunday)
[ Post Reply | Private Reply | To 338 | View Replies]

To: Openurmind
I sad anonymity, not tolerance. Protecting users identities. But I’m well aware of the intolerant want to make everyone adhere to group think and follow the herd.

And since FR enables anonymity then the only issue is a handle being misused. Meanwhile,any position is sets one in opposition from a contrary one, and since those of like mind tend to congregate, then dissent from "group think" typically results in various degrees and forms of disparagement, whether it be atheists on Quora or Reddit, etc. to Catholic sites to Slate and the DU, etc.. Yet conservatives overall are more tolerant than libs. And FR is far more mature with its judicious moderation than any other forum i have been on. But the most intolerant are such as oppose FR owner's statement that FR is

"pro-God, pro-life, pro-family, pro-Constitution, pro-Bill of Rights, pro-gun, pro-limited government, pro-private property rights, pro-limited taxes, pro-capitalism, pro-national defense, pro-freedom, and-pro America. We oppose all forms of liberalism, socialism, fascism, pacifism, totalitarianism, anarchism, government enforced atheism, abortionism, feminism, homosexualism, racism, wacko environmentalism, judicial activism, etc. We also oppose the United Nations or any other world government body that may attempt to impose its will or rule over our sovereign nation and sovereign people. We believe in defending our borders, our constitution and our national sovereignty.

And

Free Republic stands for God, family, country. We generally look to Judeo-Christian* guidance on issues of law, morality, justice, freedom, life, family and civil society. And we have a Christian self-governing, self-reliant, individual accountability & responsibility, you gotta work if able-bodied and want to eat attitude on cultural and societal issues. And a Christian pro-Constitution, original intent, pro-liberty, pro-life, pro-family, pro-gun, restricted government, small government, states rights, individual rights, free enterprise position on political and civil matters.

340 posted on 03/18/2025 5:26:18 AM PDT by daniel1212 (Turn 2 the Lord Jesus who saves damned+destitute sinners on His acct, believe, b baptized+follow HIM)
[ Post Reply | Private Reply | To 319 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 281-300301-320321-340341-357 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson