logoalt Hacker News

wahnfriedenyesterday at 12:53 PM8 repliesview on HN

Sometimes attacks happen from users being instructed to enable settings in order to achieve something regardless of whether you’d expect them to have a reason to use the setting


Replies

attyyesterday at 12:59 PM

Sure, sometimes people get social engineered into taking money from their bank account and giving it to criminals. Should banks stop allowing withdrawals?

show 1 reply
tyromaniacyesterday at 1:27 PM

If someone is willing to click on build version 5 times and then gets a mystery prompt about dev mode, and still goes along with the next 4 steps I think they were gonna get hacked a billion different other ways

lucideeryesterday at 4:56 PM

The solution to social engineering can't be to remove useful features - you can socially engineer people to do literally anything, you can have someone walk to their bank, withdraw cash & fly to you with it with a dating scam: there are literally no boundaries once you get into that area of security. Digitally, you combat that through UX, messaging & education.

show 1 reply
docmarsyesterday at 4:09 PM

Then maybe the best course of action is Google adding a warning before enabling certain settings that help normies avoid these attacks.

Along the lines of "Are you being asked to do this by someone else? Be cautious, as your device could become compromised."

show 2 replies
atoavyesterday at 1:59 PM

Sometimes people fall down the stairs in their own homes. That doesn't mean the government should mandate everybody to wear helmets at home does it?

A measure needs to be in proportion to the actual risk it seeks to mitigate.

show 1 reply
orduyesterday at 2:45 PM

I think that these victims are paid by the likes of Google to create a precedent. It is unbelievable stupid scheme to fall to.

show 1 reply
Hizonneryesterday at 1:25 PM

... and it is stupid to try to protect cretins who would do that by screwing everybody else.

redsocksfan45yesterday at 4:03 PM

[dead]