Live data from Hacker News

Ask HN: Why is company letterhead a valid form of auth in 2022?

news.ycombinator.com

1–10 of 37 posts

Ask HN: Why is company letterhead a valid form of auth in 2022?

#1
After filing a violation with twitter support for an account impersonating an opensource project I work on (posting fake news, etc) Twitter has asked that I verify myself as being part of the organisation being impersonated by providing a copy of my business card or a signed company letterhead.

This is not the first time I've been challenged to provide a company letterhead as a form of authentication by a large, reasonably sophisticated company. How is this still considered quality best practice?

Re: Ask HN: Why is company letterhead a valid form of auth in 2022?

#2
Twitter is one (of several) companies that have used your required phone number for marketing purpose. How is it you think they have any care about best practices?

Anyway, this is about shifting liability with minimal effort. As such, I'd consider it best practice. Of course, I'm using that term in a different way than you, but you just need to appreciate the goal here. It's not at all about "authenticating" you as a heretofore unknown, authorized member of the org -- that's extremely difficult, even at small scale.

Re: Ask HN: Why is company letterhead a valid form of auth in 2022?

#5
post #3

Same way a passport is, I guess? 99% of organisations that ask for a passport image have no way of knowing whether it is fake or not, a letterhead is slightly easier to mock up though.

Passports have verifiable codes on them. Letterheads can be copied like word docs.

Granted that's not to say people will actually verify passports using the data, but it is there compared to a letterhead being effectively just a random doc template.

Re: Ask HN: Why is company letterhead a valid form of auth in 2022?

#6
post #3

Same way a passport is, I guess? 99% of organisations that ask for a passport image have no way of knowing whether it is fake or not, a letterhead is slightly easier to mock up though.

I don't know how you all do it in the US, but ever since Biometrics was introduced after 9/11 we have had open public access to verify passports on the Swedish Police website. https://polisen.se/en/services-and-permits/passport-and-nati...

and we have a central organisation called PRADO with information on how to verify any EU country's passport. https://www.consilium.europa.eu/prado/en/prado-start-page.ht...

Re: Ask HN: Why is company letterhead a valid form of auth in 2022?

#7
post #3

Same way a passport is, I guess? 99% of organisations that ask for a passport image have no way of knowing whether it is fake or not, a letterhead is slightly easier to mock up though.

I don't know how you all do it in the US, but ever since Biometrics was introduced after 9/11 we have had open public access to verify passports on the Swedish Police website. https://polisen.se/en/services-and-permits/passport-and-nati... and we have a central organisation called PRADO with information on how to verify any EU country's passport. https://www.consilium.europa.eu/prado/en/prado-start-page.ht...

The PRADO website says it is not (yet) fit for purpose and you should go to your own country's agency to verify passports. The fact of the matter is that for most EU countries, you simply cannot verify them unless you are a government agency. I have had to figure out ways around this professionally, so I am reasonably certain this is accurate (at least up to a year or two ago).

Re: Ask HN: Why is company letterhead a valid form of auth in 2022?

#8
I have as well. Even a really long time ago, so it sounds like a long lasting habit.

It reminds me of how lawyers are happy to accept signatures by fax. You could be a rather lousy forger, yet because of the huge and extremely black pixels, still make a passable forged signature over fax. You can even tape a real signature on the page, or make numerous corrections, because the resolution simply cannot show any of those details. There is not much one would consider reliable about a faxed document.

Post reply on HN