Hacker News new | ask | show | jobs
by cosmiccatnap 1094 days ago
I'm surprised we still post articles from Krebs on here. I'm also surprised people think SMS is a safe mechanism for verification or validation
1 comments

Is Krebs bad?
Probably referring to the use of poor sources in its past reporting, notably with Ubiquiti.

https://www.theregister.com/2022/03/30/ubiquiti_brian_krebs/

The Register is one of the last publications that you should trust to make claims about the quality of other news sources.

I've personally had them grossly misrepresent a technical writeup I'd posted online, and then completely ignore attempts to correct them.[1] I've heard similar accounts from other people who work in information security.

I don't even read their articles anymore. They're the IT equivalent of the National Enquirer, if you ask me.

[1] I'd written up a discovery about how (back in the early 2010s) Motorola phones sent and received sensitive data insecurely, including data related to any configured Exchange ActiveSync account. The Register claimed (in the headline as well as the article!) that the issue was related to Exchange, i.e. that Microsoft was partly responsible, when the issue was entirely limited to communication between the phones and Motorola's internet-facing APIs. Literally every other publication got it right, but The Register, a supposed tech news site, took it as a chance to dunk on Microsoft and wouldn't correct their claims.

Every news source is, especially when you find yourself the subject of their reporting.

Krebs doesn't always get it right, but he tries. Trust-but-verify.