• 2 Posts
  • 1.07K Comments
Joined 2 years ago
cake
Cake day: August 4th, 2023

help-circle


  • Nah that was Windows XP, where the hard drive was not encrypted by default, and the password was stored in a hashed file on the computer itself, freely accessible via any boot stick. Actually cracking it still took some time (below 7 characters a few minutes, 7 about 1h, 8 chars up to 24h, longer… LONG). But if it was a common word, then a dictionary attack with a long enough word list (most word lists have like 400k words or so) would get it in seconds either.

    The funny thing with Windows XP was that since none of the data was encrypted, you could simply delete the password hash and set a flag in the registry and you would boot right into Windows with no password at all, and were then prompted to set a new password. That didn’t work since Windows 7 anymore.


  • You can buy a hardware keystroke recorder for a few bucks. Just plug it between keyboard and computer and it logs all inputs. Once they have the boot password (and maybe a bunch of others), installing malware and exfiltrating data is pretty straightforward. Doesn’t require a lick of IT knowledge either.

    Bit more challenging on a laptop without external keyboard, but there are hardware solutions as well, though they’d require tinkering with your device.

    Phones are harder to gain access to. Honestly if I wanted to get into your phone, I’d probably try to set up hidden cameras in spots where you are likely to enter your PIN (bed, toilet) somewhere under the ceiling and angled straight down. I’d probably try to switch the phone off as well any chance I got (long press the start button) so that you’d be forced to boot up and enter the PIN at any given opportunity to max my chances.

    Actually hacking secure boot / accessing data from encrypted drives is beyond casual hackers, unless you don’t regularly update your devices and there are some active exploits published.

    But seriously, low effort password sniffing is still the biggest vulnerability out there.


  • Lemmy is the only text-based social media I use, other than PieFed (which is practically the same, and fully compatible). If there was a PieFed client with a nice UI, I’d switch fully in a heartbeat. Unfortunately the only client seems to be Interstellar, which is functional but lacking (and ugly).

    I do still use Instagram, but more so as a photo backup solution than active social media. PixFed or whatever it was called didn’t work for me since nobody can guarantee that the server I chose will actively be maintained long term.