Hacker News new | past | comments | ask | show | jobs | submit login

> It's pretty much always email > standard user > administrator

What does this mean?




believe it or not, most users dont run around downloading random screensavers or whatever. Instead they are receiving phish emails, often from trusted contacts who have recently been compromised using the same style of message that they are used to receiving, that give the attacker a foothold on the computer. From there, you can use a commonly available insecure legacy protocol or other privilege escalation technique to gain administrative rights on the device.


standard user: why can't I open this pdf? It says Permission Denied

dumb admin: let me try .... boom game over man


It's the attack path.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: