Jump to content

My Channel Was Deleted Last Night.

CPotter
45 minutes ago, frog water said:

As really thinking about it their are easy possible security features that you think should be in place that aren't , kina makes you wonder why aren't they a thing and what is more important to youtube .

Cost, usability and to avoid support calls.

 

So for example an obvious fix would be if session cookie suddenly jumps to a new IP  then request reauthentication.

Except now they have one more piece of data to track and a bunch of support calls from people asking why they keep getting logged out while traveling.

 

Not impossible to do though, Azure and others can use location, device, configuration and other additional factors to check the session is still legit. They would also only work with a managed device.

 

There is actually quite a lot done these days to protect your session, when I were a lad you didn't even need the funky PDF as I could have extracted your session using a JavaScript embedded in a URL (cross-site scripting) or worse still Cross Site Request Forgery would have let me send commands through your browser (with your session cookie) just because you visited my website!

 

Good to see everything back in order.

Link to comment
Share on other sites

Link to post
Share on other sites

This video is a great reminder to be vigilant to emails that you get. Even the most security minded people can fall for a phishing scam. My thoughts and prayers to the LMG team.

Desktop: AMD Ryzen 9 5900X, MSI MPG X570 Gaming Edge WiFi, MSI RTX 3080 Gaming X Trio, 64GB Trident Z RGB 3600 MT/s RAM, Windows 11 Pro

Custom Built NAS: AMD Ryzen 7 3700X, MSI B550M PRO-VDH WiFi ProSeries, MSI RTX 2060 Super Gaming X, 128GB LPX Vengeance 3200 MT/s RAM, TrueNAS Scale

Custom Built Router: Intel Core i5 10400, Asrock B460M Steel Legend, 8GB 3000 MT/s RAM, OPNSense

Phone: iPhone 15 Pro Max 512 GB T-Mobile

Work Laptop: Dell XPS 15, Intel Core i7-11800H, RTX 3050 TI, 32 GB 3200 MT/s RAM, Windows 11 Education

Tablet: iPad Pro 11" (2021) 256 GB

Dogs: Male Labrador Retriever and Male Pomeranian Chihuahua Mix

Link to comment
Share on other sites

Link to post
Share on other sites

Was it my brother-in-law who hacked into your account? Wouldn't be surprised as he does things like this all the time. Anyways, an anti-virus might have saved you from this kind of attack. Windows Defender isn't very good.

Link to comment
Share on other sites

Link to post
Share on other sites

Glad the channel is back! I get Linus' criticism of Google on their lack of/not great communication with him during the resolution process. But I would think they know they are dealing with someone who has had their account(s) compromised. They might be worried/suspicious that hackers themselves are impersonating you as an attempt to gain information (how much they've discovered and what they're doing to repair it), maybe in an attempt to fight back or keep it longer. Especially if you're communicating via email  (as shown in the video). Which is understandable. Although, we don't have all the information, maybe he was able to confirm his identity somehow. 

Link to comment
Share on other sites

Link to post
Share on other sites

I was super confused when on the "Subscriptions" tab, seeing Teckquickie & LTT missing.

Link to comment
Share on other sites

Link to post
Share on other sites

#LinusTechRIPs

 

I'm disappointed with myself for not following the interwebz yesterday and missing out on the chance to make that joke.

Aerocool DS are the best fans you've never tried.

Link to comment
Share on other sites

Link to post
Share on other sites

A simple mitigation against this is to use Group Policy to make your documents and download folders no execute.

 

Any malware saved there, like if you download a "pdf" or try to open it, you will get an error from Windows.

Link to comment
Share on other sites

Link to post
Share on other sites

i found that microsoft is also trying to stop this due to the text saying "microsoft defender smartscreen" in tesla2ai.net and im gonna investigate the code in it

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, adamhawree said:

i found that microsoft is also trying to stop this due to the text saying "microsoft defender smartscreen" in tesla2ai.net and im gonna investigate the code in it

mhm found it in the code : <!--
Copyright (C) Microsoft Corporation. All rights reserved.
Use of this source code is governed by a BSD-style license that can be
found in the LICENSE file.
-->

Link to comment
Share on other sites

Link to post
Share on other sites

I'm sure I'm very late to the topic, but as an IT specialist in an organization that grew in the approximate same amount, including a service like KnowBe4 has been super valuable.  They have training, phish links, testing to bring awareness to those that don't know.  Dramatic change in employee reactions.

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, Spotty said:

Watch the video they posted a link to.

I get that most of the world does not use ASCII and that the particular unicode character needs to exist...but boy, MS really should add in at least some form of protection against executable file types.  This trick is something that I could see even a seasoned IT person falling for if they see it on someone's computer.  If anything, the presence of a file where the unicode character is present at a non-zero index should instantly set up a red flag (and a massive warning message before it's allowed to be run).

 

 

Regarding to the video, YouTube/Google really does need to change...this has been going on for literally years now and the fix could be so simple as well.  It would be interesting to see the internal conversations at Google regarding this, I'm betting it's along the lines "We should do this" "Okay, lets do a study on impact to users" [Study takes a half a year] "Lets do an experimental deployment and see if users complain".  (Too many management decisions to be made in-between, Google no longer is an agile company).

 

Changes I'd like to see on Google's end:

  - Changing password requires the 2FA

  - Changing the 2FA requires the password

  - Changing channel name password/2FA

  - Changing channel name locks livestreaming for 24 hours or at minimum if the name include "Tesla" or "Mr Beast" it should be limited to 24 hours

  - Sessions should be linked to IP...or at minimum geolocated to roughly the same area.

 

While blame still falls on Linus and his team, it's a difficult decision really when allowing things like zip/rar files.  There was a time-clock company I had to work with that would constantly require me to send them files after renaming the .zip file to .zipc...simply because their email server bounced all zip files (and even then it was a struggle getting them necessary files that was needed for them to fix a mix up on their end).

 

Even with proper training, I could see how a normal user could make the mistake as well or how preventing this could also create a hindrance to the company (slowing down communication or putting up too many barriers to the point sponsors might not want to work with you).  Even with proper training as well, you will have users who break that since it creates too much of an inconvience.

 

One thing I did when I managed the Exchange servers at my place of work before was anytime an email came through with a zip file, I set a very bold and very obvious text prepended to the beginning of the file stating "Treat zip files with caution contact [my name, phone, and email] me before opening or ask the sender to send the attachment without the zip file".  I only had to deal with it once or twice a week, but in one case it actually was a poisoned docx file; so it was well worth...I actually had a specific offline thin client that I used for it...so everytime I reset the machine it would essentially go back to fresh as well (technically it still could have infected the machine and traveled to the USB the next time I plugged one in but that was within my tolerances).

 

3735928559 - Beware of the dead beef

Link to comment
Share on other sites

Link to post
Share on other sites

I'm actually relieved that Linus isn't punishing whoever is the culprit, generally yelling and scolding people who don't know any better about what they did only makes the entire situation worse. Instead, I think a global, companywide training session about what happened and how to prevent it in the future is a much, MUCH better way at mitigating the issue in the future.

 

I'm wondering if there would even be any way to mitigate the issue in the future (other then Google picking up the slack and doing what Linus said), especially since as the saying goes, your security is only as strong as your weakest link. Regardless, glad the channel is back!

Keep in mind that I am sometimes wrong, so please correct me if you believe this is the case!

 

"The Nvidia Geforce RTX 3050 is brutally underrated"

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, CurryMantou said:

Two lessons: Don't open suspicious emails. Wear pants.

I don't know. Seems weird to have cameras all over the inside of your house, but maybe that's just me.

Zen 3 Daily Rig (2022 - Present): AMD Ryzen 9 5900X + Optimus Foundations AM4 | Nvidia RTX 3080 Ti FE + Alphacool Eisblock 3080 FE | G.Skill Trident Z Neo 32GB DDR4-3600 (@3733 c14) | ASUS Crosshair VIII Dark Hero | 2x Samsung 970 Evo Plus 2TB | Crucial MX500 1TB | Corsair RM1000x | Lian Li O11 Dynamic | LG 48" C1 | EK Quantum Kinetic TBE 200 w/ D5 | HWLabs GTX360 and GTS360 | Bitspower True Brass 14mm | Corsair 14mm White PMMA | ModMyMods Mod Water Clear | 9x BeQuiet Silent Wings 3 120mm PWM High Speed | Aquacomputer Highflow NEXT | Aquacomputer Octo

 

Test Bench: 

CPUs: Intel Core 2 Duo E8400, Core i5-2400, Core i7-4790K, Core i9-10900K, Core i3-13100, Core i9-13900KS

Motherboards: ASUS Z97-Deluxe, EVGA Z490 Dark, EVGA Z790 Dark Kingpin

GPUs: GTX 275 (RIP), 2x GTX 560, GTX 570, 2x GTX 650 Ti Boost, GTX 980, Titan X (Maxwell), x2 HD 6850

Bench: Cooler Master Masterframe 700 (bench mode)

Cooling: Heatkiller IV Pro Pure Copper | Koolance GPU-210 | HWLabs L-Series 360 | XSPC EX360 | Aquacomputer D5 | Bitspower Water Tank Z-Multi 250 | Monsoon Free Center Compressions | Mayhems UltraClear | 9x Arctic P12 120mm PWM PST

Link to comment
Share on other sites

Link to post
Share on other sites

Meanwhile I use my VPN and every other page Google is having me input captcha to show I'm not a bot. Oh and my Google account was compromised the other year and it got banned for content uploaded to the drive and there was no one from google I could talk to to get my account back so I lost my emails and all my google photos. Thanks google. 

Link to comment
Share on other sites

Link to post
Share on other sites

43 minutes ago, Sir Beregond said:

I don't know. Seems weird to have cameras all over the inside of your house, but maybe that's just me.

When you have potential for breaking into your house because famous, you pretty much need cameras at all times. Matters a lot more in states where you can shoot to kill home invaders so you can show they broke in and such. But its almost always about making sure the house and whatever in it is safe.

 

There has been quite a few youtubers that have had their house broken into, thats why hes been trying VERY hard to hide where his house is, and having a few stupid mistakes like listing its exact address on live stream didnt help. People suck.

 

 

On topic: I still dont think they needed access to the Youtube channel. Just having machines that can deal with potential issues like this as disposable and shut down fast without any real threat for just marketing and potential deals sounds a lot safer. But theyve only had two issues for such a large channel.

Link to comment
Share on other sites

Link to post
Share on other sites

Well, we know for a fact, according to the video, that it was most definitely not colton.

Link to comment
Share on other sites

Link to post
Share on other sites

Im really glad you got this sorted. It sounds like that youre implementing some necessary processes. Can i suggest one to look at... Email gateway...

Im a sysadmin and we have had Mimecast implemented since 2010... yes it can be expensive (£20k over 3yrs for 100 users) but it really does help and it will alleviate a lot of worry.

i have it nailed down so that any attachment gets striped and users get a safe version. (which would have stopped your attack before it began).

Theres so many security features too many mention here, but you should have a look.

anyway, (if you do see this, it will prolly get lost in the ether) keep up with the good work and stay safe.

Link to comment
Share on other sites

Link to post
Share on other sites

Kinda amusing Youtube doesn't prompt for a password to change a channel name.  

 

And install an actual AV on the machines of people who are public-facing.  You don't need to do all this NSA shit scrubbing emails in a VM on an air gapped blah blah.   An actual AV wouldn't allow a random executable go off and query shit from browser folders.

 

Workstation:  13700k @ 5.5Ghz || Gigabyte Z790 Ultra || MSI Gaming Trio 4090 Shunt || TeamGroup DDR5-7800 @ 7000 || Corsair AX1500i@240V || whole-house loop.

LANRig/GuestGamingBox: 9900nonK || Gigabyte Z390 Master || ASUS TUF 3090 650W shunt || Corsair SF600 || CPU+GPU watercooled 280 rad pull only || whole-house loop.

Server Router (Untangle): 13600k @ Stock || ASRock Z690 ITX || All 10Gbe || 2x8GB 3200 || PicoPSU 150W 24pin + AX1200i on CPU|| whole-house loop

Server Compute/Storage: 10850K @ 5.1Ghz || Gigabyte Z490 Ultra || EVGA FTW3 3090 1000W || LSI 9280i-24 port || 4TB Samsung 860 Evo, 5x10TB Seagate Enterprise Raid 6, 4x8TB Seagate Archive Backup ||  whole-house loop.

Laptop: HP Elitebook 840 G8 (Intel 1185G7) + 3080Ti Thunderbolt Dock, Razer Blade Stealth 13" 2017 (Intel 8550U)

Link to comment
Share on other sites

Link to post
Share on other sites

18 minutes ago, My_BallsUK said:

Im really glad you got this sorted. It sounds like that youre implementing some necessary processes. Can i suggest one to look at... Email gateway...

Im a sysadmin and we have had Mimecast implemented since 2010... yes it can be expensive (£20k over 3yrs for 100 users) but it really does help and it will alleviate a lot of worry.

i have it nailed down so that any attachment gets striped and users get a safe version. (which would have stopped your attack before it began).

Theres so many security features too many mention here, but you should have a look.

anyway, (if you do see this, it will prolly get lost in the ether) keep up with the good work and stay safe.

Any good endpoint AV tool should have stopped this as well.  It's a failing of the whole security stack, which includes the training of staff.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Shimejii said:

When you have potential for breaking into your house because famous, you pretty much need cameras at all times. Matters a lot more in states where you can shoot to kill home invaders so you can show they broke in and such. But its almost always about making sure the house and whatever in it is safe.

 

There has been quite a few youtubers that have had their house broken into, thats why hes been trying VERY hard to hide where his house is, and having a few stupid mistakes like listing its exact address on live stream didnt help. People suck.

 

 

On topic: I still dont think they needed access to the Youtube channel. Just having machines that can deal with potential issues like this as disposable and shut down fast without any real threat for just marketing and potential deals sounds a lot safer. But theyve only had two issues for such a large channel.

I guess makes sense. Just seems weird having cameras watching you on your computer in your underwear.

Zen 3 Daily Rig (2022 - Present): AMD Ryzen 9 5900X + Optimus Foundations AM4 | Nvidia RTX 3080 Ti FE + Alphacool Eisblock 3080 FE | G.Skill Trident Z Neo 32GB DDR4-3600 (@3733 c14) | ASUS Crosshair VIII Dark Hero | 2x Samsung 970 Evo Plus 2TB | Crucial MX500 1TB | Corsair RM1000x | Lian Li O11 Dynamic | LG 48" C1 | EK Quantum Kinetic TBE 200 w/ D5 | HWLabs GTX360 and GTS360 | Bitspower True Brass 14mm | Corsair 14mm White PMMA | ModMyMods Mod Water Clear | 9x BeQuiet Silent Wings 3 120mm PWM High Speed | Aquacomputer Highflow NEXT | Aquacomputer Octo

 

Test Bench: 

CPUs: Intel Core 2 Duo E8400, Core i5-2400, Core i7-4790K, Core i9-10900K, Core i3-13100, Core i9-13900KS

Motherboards: ASUS Z97-Deluxe, EVGA Z490 Dark, EVGA Z790 Dark Kingpin

GPUs: GTX 275 (RIP), 2x GTX 560, GTX 570, 2x GTX 650 Ti Boost, GTX 980, Titan X (Maxwell), x2 HD 6850

Bench: Cooler Master Masterframe 700 (bench mode)

Cooling: Heatkiller IV Pro Pure Copper | Koolance GPU-210 | HWLabs L-Series 360 | XSPC EX360 | Aquacomputer D5 | Bitspower Water Tank Z-Multi 250 | Monsoon Free Center Compressions | Mayhems UltraClear | 9x Arctic P12 120mm PWM PST

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Shimejii said:

When you have potential for breaking into your house because famous, you pretty much need cameras at all times. Matters a lot more in states where you can shoot to kill home invaders so you can show they broke in and such. But its almost always about making sure the house and whatever in it is safe.

 

There has been quite a few youtubers that have had their house broken into, thats why hes been trying VERY hard to hide where his house is, and having a few stupid mistakes like listing its exact address on live stream didnt help. People suck.

 

 

On topic: I still dont think they needed access to the Youtube channel. Just having machines that can deal with potential issues like this as disposable and shut down fast without any real threat for just marketing and potential deals sounds a lot safer. But theyve only had two issues for such a large channel.

 

Next up Linus creates a smart turret system for his home defense 

Link to comment
Share on other sites

Link to post
Share on other sites

EDIT - >>>NOW THIS GOES TO THE NORMAL LTT youtube


is it just me or is there another FAKE LTT on youtube at the moment?

i searched for "linus" and "linus tech tips" and found the same thing both times

you can see the URL to the fake account in the bottom left but in the search results it looks very real

clicking on it takes me to a totally fake account

(tagging LMG staff and moderators in the hope they see this)

@CPotter @LinusTech @Crunchy Dragon @mynameGeoff @BellLMG @Shahrad

FAKE LTT.jpg

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, lukeis2k20 said:

is it just me or is there another FAKE LTT on youtube at the moment?

If you click on it you'll see it directs you to the actual LTT channel.

F@H
Desktop: i9-13900K, ASUS Z790-E, 64GB DDR5-6000 CL36, RTX3080, 2TB MP600 Pro XT, 2TB SX8200Pro, 2x16TB Ironwolf RAID0, Corsair HX1200, Antec Vortex 360 AIO, Thermaltake Versa H25 TG, Samsung 4K curved 49" TV, 23" secondary, Mountain Everest Max

Mobile SFF rig: i9-9900K, Noctua NH-L9i, Asrock Z390 Phantom ITX-AC, 32GB, GTX1070, 2x1TB SX8200Pro RAID0, 2x5TB 2.5" HDD RAID0, Athena 500W Flex (Noctua fan), Custom 4.7l 3D printed case

 

Asus Zenbook UM325UA, Ryzen 7 5700u, 16GB, 1TB, OLED

 

GPD Win 2

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×