Yesterday, in connection with the hacking of Navalny, a colleague from the Echo website asked me to write something about email hacking, what to do and where to run, since just in February of last year my accounts were hacked. Back then, few people cared about how I fiddled with their restoration, but, of course, now that Navalny himself was hacked, they ask what was there, how did you escape. Zealously, yes.
I have no doubt that both hacks (and many others) were carried out by the same organized group. How close she is to government officials is anyone’s guess, but to me personally, everything is quite obvious. I still don’t know what the hacking of my accounts was connected with, I only know that it happened a day after I spoke about the physical persecution of me by the Nashists.
My computers were not confiscated or searched, and my passwords were somewhat different from the legendary 12345. Moreover, when, a few hours before the successful attack, the first one was launched (services send notification letters about password reminder requests), the passwords were changed. However, this did not help; that same night, mail, blog , Twitter and Facebook were hacked. There is no doubt that the weak point turned out to be mail, with the help of access to which passwords for other services are then requested and obtained. Navalny’s accounts were apparently hacked using the same scheme. Interestingly, the evolution of hacking reflects the decline in the popularity of LiveJournal - it is broken less and less often. My blog, which is broadcast on LiveJournal, was hacked, but the LiveJournal itself was not touched. Navalny also limited himself to Twitter.
The victim’s algorithm of actions is approximately the same as when money is stolen from a credit card: block accounts, regain control over them, change passwords and the access system to a more sophisticated one. First of all, this is a key service - mail, fortunately, the mechanisms of mail services, as a rule, without any problems, without entering into correspondence with responsible people, allow you to return your account, even if the password was changed by an attacker.
It’s a similar story with Facebook: it comes back based on the security question. Twitter is a completely different matter. There is no representative office in Moscow, but the Californian office did everything possible to protect itself from the user and distance itself as far as possible from him. Official contact - notifications-support@twitter.zendesk.com, as well as @podderzhka. The first one must be notified in English (you can immediately attach a scan of a document with your name and surname written in English, for example, a license or a foreign passport, they will still ask for it later), the second one can be notified in Russian. The problem is that the office in California is small, and there are a lot of hacked cases - don’t be surprised if days, or even weeks, pass between the appointment of a hearing on your case (they will assign a ticket and send you a number by mail) and the decision on it. In addition, the 11-12 hour time difference also plays a role - you write, and everyone will still sleep there for 8 hours, and on weekends no one can easily work. In this sense, I bow to the talent of Anna Veduta , Navalny’s press secretary, who gnawed out some additional contacts and returned Alexey’s Twitter in less than a day. Alas, I don’t have such a Veduta, and even with an additional personal contact in the Twitter office, I had to wait for my account for almost a week, undergoing noticeable withdrawal symptoms.
There is also a way to spit on old accounts and just create new ones (it seems that my colleagues Ira Vorobyova, Ksenia Larina and Volodya Varfolomeev did when they broke their LiveJournal) but it’s a pity, and everyone is used to it - when else will you be able to notify all your contacts about moving are inconvenient, especially with a large number of readers, friends, etc.
It is worth recognizing that the hacker is making your life difficult in any case: from now on, if you do not become paranoid, you will forever doubt the inaccessibility of your data and will be forced to sacrifice a number of conveniences, as well as learn something in order to increase the level of security of your accounts, First of all, mail, through which everything breaks down. If your service allows it, it makes sense to set up two-step authorization, this is when you link your phone number to your account and, when you log in from a new device, you receive an SMS with a confirmation number, which is a one-time key to your mailbox. Secondly, it is worth complicating the actual passwords as much as possible, for which you can use password generation services, another thing is how you will remember these gobbledygook, I think the advice here is useless, everyone decides in their own way. But your carefree life will obviously be spoiled, including by the fact that you will think about the content of letters and personal messages on social networks, destroy or resave confidential or critical information for you, in a word, it’s hell.
Password theft is also possible with the help of malicious programs (in common parlance - viruses), so it does not hurt to install a good, preferably a paid antivirus on your computer, even on a Mac. Unless, of course, you are still a complete conspiracy theorist and don’t think that antivirus manufacturers themselves steal passwords with their help. Another thing is that for people like me, this is a dead poultice, since I use more than a dozen devices, some of which belong not to me, but to the employer, and I cannot control their safety. But it still doesn’t hurt to secure at least what is possible.
The most unpleasant thing is that all these measures will not guarantee complete security for your accounts and peace of mind for you personally. If they want to hack you, they will hack you, no matter what. Not by selection, but by Trojan, not by Trojan, but by seizure of computers, not by seizure, but by “politely requesting” your passwords from the service, etc., there are many ways. Contacting law enforcement agencies will not help you in the slightest, unless you have nowhere to spend your time and nerves... I myself have not tried to do this, having assessed the reviews of other victims and the experience of hacking and DDoS attacks on media sites - no such results there were no appeals, and according to common sense, there could not have been. As with ordinary physical security, cybersecurity in our country is the work of the drowning people themselves. The situation is such that if you don’t walk around with an injury and don’t carry a baseball bat in the car, well, it’s your own fault. So in the virtual space, arm yourself as much as possible.
However, this is just my opinion; next Sunday we will make a point on this matter, where more competent specialists will speak out.