Live data from Hacker News

The “Cobra Effect” that is disabling paste on password fields

troyhunt.com

141–150 of 450 posts

Re: The “Cobra Effect” that is disabling paste on password fields

#141

Earlier quoted context omitted.

Around here every bank require 2fa for logon and then again for signing payments (although you can queue and batch sign a number at a time. )

Barclays in the UK does 2fa if you order it, otherwise this strange bit with just parts of the password. They also have the most complicated 2fa I've seen. You get a pocket-calculator-like device where you need to insert your card (chip and pin type), then you enter your personal code, and then you do a challenge-response thing where you enter a code generated from the website into the device, and it responds with a…

> You get a pocket-calculator-like device where you need to insert your card (chip and pin type), then you enter your personal code, and then you do a challenge-response thing where you enter a code generated from the website into the device, and it responds with a number you have to type into the website.

Such a thing is rather common in The Netherlands, though it's often not a second factor but just the way you log in to online banking. It avoids having you remember yet another password, instead you just use the same card and PIN you need "offline".

Side note: At the end of 2014 Rabobank (one of the banks with such a system) replaced those devices (which they called "random readers") with "Rabo scanners", which have a built-in camera to automatically read an image from the website instead of having you manually enter a code.

Re: The “Cobra Effect” that is disabling paste on password fields

#142
post #141

Earlier quoted context omitted.

Barclays in the UK does 2fa if you order it, otherwise this strange bit with just parts of the password. They also have the most complicated 2fa I've seen. You get a pocket-calculator-like device where you need to insert your card (chip and pin type), then you enter your personal code, and then you do a challenge-response thing where you enter a code generated from the website into the device, and it responds with a…

> You get a pocket-calculator-like device where you need to insert your card (chip and pin type), then you enter your personal code, and then you do a challenge-response thing where you enter a code generated from the website into the device, and it responds with a number you have to type into the website. Such a thing is rather common in The Netherlands, though it's often not a second factor but just the way you log…

> though it's often not a second factor but just the way you log in to online banking.

That's still 2FA though, isn't it? You're proving to the server that you have the card and the pin.

Re: The “Cobra Effect” that is disabling paste on password fields

#144

Earlier quoted context omitted.

It's amazing to me how insecure email is these days. If you know somebody's email, and you have a plausible reason to have a conversation with them, you can very easily take over their email account and reset the password on every account attached to it. I often wonder how much the security of email (and by extension, every other account online) depends on people just not knowing how simple and easy it is to break in…

Could you give an example of how it is possible to take over an email account just by having an e-mail conversation with the owner?

me: Hi Mate, what is your email password?

email recipient: Pasword123

me: thanks.

JOB DONE :-)

Re: The “Cobra Effect” that is disabling paste on password fields

#145
post #112
post #87

Is it really necessary to portray an initiative to wipe out dangerous snakes as self-interested and imperialist?

He never described the _initiative_ as imperialist, just the British rulers. Since the British rule of colonial India is virtually the dictionary definition of imperialism, I'll go ahead and call the author's word choice reasonable.

While you're in the dictionary you might look up the word portray.

Re: The “Cobra Effect” that is disabling paste on password fields

#146
post #144

Earlier quoted context omitted.

Could you give an example of how it is possible to take over an email account just by having an e-mail conversation with the owner?

me: Hi Mate, what is your email password? email recipient: Pasword123 me: thanks. JOB DONE :-)

Well, I was hoping for something at least a little bit more sophisticated.

Re: The “Cobra Effect” that is disabling paste on password fields

#147
post #114

Earlier quoted context omitted.

Yes. This is to protect against attackers obtaining your full plaintext password on your end, for example by phishing or installing keyloggers. In practice this is a much bigger security threat in the online banking world than someone doing the same by compromising the bank's systems - even if that were to happen they can easily re-verify your identity and issue you with a new password, and you really shouldn't be us…

How does this prevent key logging attacks? You still type in those characters. And secondly, that just immediately made it a hell of a lot easier to brute force your way through the passwords!

It asks for different characters from the password each time. So it'll ask for the 1st, 4th, and 5th characters. Next time you go to login it'll ask from 2nd, 8th, 14th. So a key logger is only getting a small portion of the password each time.

Re: The “Cobra Effect” that is disabling paste on password fields

#148
post #120

Earlier quoted context omitted.

You're right, of course, but it's also true that in a real life environment, you've already found a polite way to say "that's dumb" three times this morning and you're starting to pick your battles.

This! Dilbert is a documentary not a cartoon. Devs work for businessfolk. Businessfolk have the control call the shots. Sure they'll listen to devs but get the final say.

Couch your suggestions in business terms? user engagement decreases when you don't let them save their passwords or some such drivel. honestly if you think businessfolk call all the shots, you may have a broken business relationship

Re: The “Cobra Effect” that is disabling paste on password fields

#149
post #54

Earlier quoted context omitted.

Why though? A .txt file on the desktop is actually probably a lot more secure than using the same shitty password on every site.

A friend may get tempted to sneak a peek.

You may want to get more trustworthy friends ...

Re: The “Cobra Effect” that is disabling paste on password fields

#150

Earlier quoted context omitted.

Around here every bank require 2fa for logon and then again for signing payments (although you can queue and batch sign a number at a time. )

Barclays in the UK does 2fa if you order it, otherwise this strange bit with just parts of the password. They also have the most complicated 2fa I've seen. You get a pocket-calculator-like device where you need to insert your card (chip and pin type), then you enter your personal code, and then you do a challenge-response thing where you enter a code generated from the website into the device, and it responds with a…

That's because they are reusing a multi-purpose device. Nationwide uses the same calculator-like device to make you sign new withdrawals with your card in the machine.

You can also use it to login with Nationwide, but they also allow login with a password, which is far simpler (and you don't need to find your card to do so either)

Post reply on HN