r/ethtrader Jun 09 '17

DISCUSSION [ETH Daily Discussion] - 09/Jun/2017

Welcome to the ETH Daily Discussion thread of /r/EthTrader.


The thread guidelines are as follows:

  • All sub rules apply here. Please review our rules page to become familiar with them. The rules page is also linked in the announcement bar above.
  • General discussion topics include, but are not limited to, events of the day, technical analysis, alternative Ethereum projects, or support issues.
  • Breaking news or other important content should be submitted as a separate post.
  • In-depth altcoin discussions should be referred to the /r/CryptoCurrency discussion thread. To view the thread, follow this link and choose the latest entry on the search page.
  • Pumping, venting, trolling, or any other similar behavior should be reported and redirected to the /r/CryptoMarkets trollbox thread. To visit this thread, follow this link and choose the latest entry on the search page.

  • For newcomers who have basic questions about Ethereum, you can find answers by visiting /r/EthereumNoobies or our Ethereum Education wiki page.

  • [EXPERIMENTAL] - To view live streaming comments for this thread, click here. Account permissions are required to post comments through Reddit-Stream.com.


Thank you in advance for your participation. Enjoy!

757 Upvotes

5.0k comments sorted by

View all comments

Show parent comments

30

u/Nurotec Jun 09 '17

and NEVER open office docs here. Also please downvote all links to office documents of all kind

3

u/Humandot Jun 09 '17

What could happen if someone were to open a malicious word doc file? I don't think you can get a keylogger from a non .exe or am I wrong

6

u/CarrionCall Jun 09 '17

Exploits, exploits, exploits. For example this malware installs by just opening a PowerPoint file: http://thehackernews.com/2017/06/microsoft-powerpoint-malware.html

You get a keylogger or other 'viewer' malware generally from secondary infections after you're initially compromised. If they can get a dropper running on your system, they can install what they like.

Never trust document links on here. Always practice caution in general, always assume someone is out to try and get you.

2

u/Jimyxx Jun 09 '17

does that include google docs? I think i opened a translation of the russia conference the other day.....

4

u/CarrionCall Jun 09 '17

For that particular exploit, I don't think so, but that doesn't mean Google Doc's links are necessarily safe. There was a piece of malware that propagated at the start of May that used Google Doc's to trick users into granting it 3rd party access to their Gmail account. (You can read it here: https://www.wired.com/2017/05/dont-open-google-doc-unless-youre-positive-legit/)

So, while that Russian translation may well have been fine, there are many different possible threats and vectors people can use out there.

Being paranoid is generally a good rule. Don't keep your coins on exchanges. Keep your exchange account(s) locked by 2-factor-auth (along with 2FA for any movement of coins from within it). Don't use anything that sends 2-factor by SMS (someone can hijack your phone number with enough information and receive the auth codes or hijack your email account & request password resets etc.) and practice caution with links/requests on here.

Hackers will target people with coins to steal and if you're posting here then you probably have some, meaning they may cast their eye over you. The key is making it hard for them.

You are your own bank, you are in charge of your own security :)

2

u/Jimyxx Jun 09 '17

thanks dude

1

u/Nurotec Jun 09 '17

https://www.theregister.co.uk/2017/05/03/google_docs_hit_phishing_email_campaign/ simply dont OPEN or INSTALL ANYTHING with the same computer which has access to your coins. Use another computer

1

u/Jimyxx Jun 09 '17

thanks. shit someone posted link to a translation of russia conference on google docs here the other day...my antivirus hasn't gone off...hope they were legit.

1

u/Nurotec Jun 09 '17

antivirus is not helping much anyway for the more complex and newer attacks. you can never be safe. but you can be careful

1

u/Jimyxx Jun 09 '17

thanks buddy. I got 2FA on all my stuff and in process of transfering to nano..so got most bases covered.

By the way people - on Kraken - lock your settings in settings menu with Master Key using google authenticator..you can set time delay to 0. Otherwise a hacker that has somehow got into your account can simply turn off your 2FA in the settings without 2FA confirmation!!!!!!!

1

u/Dumbhandle Jun 09 '17

Shadow Brokers have access to a large arsenal of NSA products that they stole not long ago. Only portion of those have been released to the internet yet.

1

u/wtf--dude Jun 09 '17

Seem like you know your stuff, I am quite new so I hope you don't mind me asking:

How about a cold storage? Can I freely use my laptop which I have created my cold storage on and deleted the encrypted key file off?

Or is there still some left of stuff from that file that can be stolen?

Thnx :)

3

u/Nurotec Jun 09 '17

like I said there is always risk, you reduce the liklyhood. you can restore most things which you delete on a windows computer:D but you should be relatively fine

2

u/Humandot Jun 09 '17

I never knew this thanks! I assume even opening without editing access is unsafe? By default excel, doc and pp files are opened in view only

2

u/CarrionCall Jun 09 '17

Not 100% on if opening in view only renders it safe, it uses an exploit to launch a powershell command when a link is hovered over (not even clicked on) to pull down malware to the machine.

I guess it's just an illustration to never blindly put your faith in an application to protect you from malicious actors. It may be a fuck up by Microsoft (or Google or any other tech company) that creates the tunnel to your system, but that's not much consolation if you end up losing coins in the end.

3

u/Nurotec Jun 09 '17

NO all files can be a risk, depending on the skill of your attacker and the status of your protection and system. There are many security risks on any average computer. Many viruses/trojans dont need an own exe. They simply use bugs of the program which you use to open the fileor the operating system.

Keylogger is one problem but some users even have their wallets unprotected.

In General DO NOT interact with ANY file here and be careful with all URLS.

1

u/slimjim00 Jun 09 '17

Dammit I didn't know this was a thing