Forum Replies Created
-
AuthorPosts
-
June 30, 2022 at 12:15 PM #1825881
It's not only about hiding stuff, it's also about keeping everything else you own secure.
Most attacks by hackers aren't directed at specific targets but at places that have recent vulnerabilities to exploit - in this case Mega.
These people will try to find the next best target to hack into until they find someone who has sufficient data stored online, so that it potentially compromises everything else that person owns. Images can be used to find out your address or habits. Maybe the fact that you have children or pets? Security cameras in- or outside your house? Maybe one can even find out the exact model on one of the photos or uploaded bills? If it's a camera connected to a wifi network a hacker could potentially gain access to those, too (although unlikely).
Nevertheless, most people who store their sensitive data unencrypted and at a single place tend not to be so tech-savvy, so one could try to brute-force their way into other accounts using the same email and password. Then try other passwords like their pet's or children's names, maybe nicknames they use in online games you were able to see on screenshots they uploaded. Add common password variations like "123petname456" or "ch1ldn4m3" etc. There are linux distros meant solely for hacking, including programs to automate individualized brute-force attacks like these.
I know too many people who also store all their login credentials including corresponding websites in a .txt file somewhere supposedly "safe"... like in their "military grade encrypted cloud storage" which in this case is Mega.
If that's not sufficient, knowing a lot about you is enough to engage in a little social engineering to get people you know, or even better, your bank to talk. And if that also doesn't work, the easiest way would be to simply infect your files with malware. One RAT and one MEGA Sync - swoop an attacker has access to everything.
You may know your way around computers and the internet, but most people still don't.
Setting up clientside encryption takes like 3-5 minutes once and everything else is handled by your device from then on.
There's absolutely no reason not to add a free and foolproof layer of security to your data.
Truthfully speaking, the above is already a possibility for anyone who engages with things on the internet, keyword OSINT. Having their mega account's encryption broken only makes them an even easier exploitation target. Especially when talking about young people who can rather easily be blackmailed into stealing their parents' credit card or sadly way worse. There's already way too much of that happening.I'd rather be a little paranoid than sorry. It really doesn't hurt.
June 11, 2022 at 5:01 PM #1818539Ohh, that's great!
I'll start doing that right away!
And thank you for the detailed explanation 😀June 9, 2022 at 5:52 PM #1817847That's really good to know. How do you normally update DS itself then? Backup the old files and merge after it's done?
-
AuthorPosts
