Live data from Hacker News

The “Cobra Effect” that is disabling paste on password fields

troyhunt.com

251–260 of 450 posts

Re: The “Cobra Effect” that is disabling paste on password fields

#251
post #212

Earlier quoted context omitted.

Man I hate those security questions with a passion. They are super weakly protected backdoors into your account. Here's how I deal with sites that require them: site: "What is your first teacher's name?" me: "'Fx| The answer is a password equivalent, so I just treat it like a password.

Doesn't work with United MileagePlus accounts, they only allow multiple choice answers!

Just give the wrong answer and keep track in your password tracker. At least social engineers can't figure that out.

Re: The “Cobra Effect” that is disabling paste on password fields

#252

Fortunately, it's not hard to get around this on desktop (for Mac at least) with an applet like Paste Typer. But when I see this on iOS it infuriates me. I use 1Password to generate strong (long) passwords and having to type them out manually is a huge PIA.

The annoying one on iOS is how often it makes me re-enter my Apple ID password. In a modal, of course, so it's impossible to bounce out to 1Password to copy the (very long and complex) password without dismissing the modal first. Sometimes I'll get a "re-enter your apple id password" modal at some random time while I'm doing something else, dismiss it to go get the password, and then have no idea how to get it back b…

This is so frustrating.

Re: The “Cobra Effect” that is disabling paste on password fields

#254

Earlier quoted context omitted.

HSBC doesn't do that any more for me -- they've moved to a Google Authenticator-like 2FA approach[1], but Lloyds[2] does - they have one username and password, and a "memorable phrase" which they clearly store as plaintext because ask for the xth, yth and zth character as a secondary security measure. Lloyds tech folk reading this -- please consider fixing this. [1] http://i.imgur.com/QCGPDWz.png [2] http://i.imgur.c…

HSBC always used a token for online banking you can either order a secure Key or for the past year or so use a mobile authenticator. The "password/memorable phrase" is only used as a secondary authentication measure and in order to initiate a token recovery procedure on the site. P.S. I still use the physical OTP token, just got a new one last month it's a Vasco Digitpass 270 supports upto 8 digit pins and it locks o…

Authy addresses the losing your phone scenario.

Edit: I realise you're probably referring to proprietary bank authenticator apps

Re: The “Cobra Effect” that is disabling paste on password fields

#255
post #180

Here in Norway, almost all financial and government institutions allow a form of authentication called BankID ( https://www.bankid.no/en/company/ ). I use the mobile variant and it works for all government related stuff like taxes, health, relocation notices and also with all banks both when logging in and paying bills, signing contracts etc. It is a legally binding identification akin to signing a paper. The procedu…

Isn't that vulnerable to MITM attacks for GSM? There have been quite a few demonstrated at DEFCON that could work very well for attacking this kind of system (on a large scale)

Would the short phrase from the website over TSL mitigate this? Even if someone could snoop the GSM, there would still be some (hopefully random) string that only the web server and client would know.

Re: The “Cobra Effect” that is disabling paste on password fields

#256

TradeKing went full idiot and disabled entering your password by keyboard completely. They implemented an on-screen keyboard and there's no way to opt out. Their support forum is full of angry customers, people who can't use their screen readers anymore, etc. They argue [1] it's to protect their customers from key loggers. [1]: https://community.tradeking.com/forum/categories/suggestions...

Cause key loggers don't track mouse clicks. Lol.

Two factor is their best bet.

Re: The “Cobra Effect” that is disabling paste on password fields

#257
post #211

It always amazes me that someone is hired to implement strong security and they come up with things like paste-blocking. Or "security questions." Security questions are a social engineers best friend. Unless you're savvy and your answers are all strong passwords themselves, and if they are you're probably using keepass or something like it with 400+ bit passwords and you hate wasting time on security questions too.

United MileagePlus just switched to security questions that only allow multiple choice answers. Some of the questions only have 12 valid answers. Compare that with even a weak password! Unbelievable.

I got caught by that the other day, too, and grabbed a screenshot. Crazy. Guess I'll pick my favorite artist from their exhaustive list.

http://i.imgur.com/DWKiy2a.jpg

Re: The “Cobra Effect” that is disabling paste on password fields

#258
post #254

Earlier quoted context omitted.

HSBC always used a token for online banking you can either order a secure Key or for the past year or so use a mobile authenticator. The "password/memorable phrase" is only used as a secondary authentication measure and in order to initiate a token recovery procedure on the site. P.S. I still use the physical OTP token, just got a new one last month it's a Vasco Digitpass 270 supports upto 8 digit pins and it locks o…

Authy addresses the losing your phone scenario. Edit: I realise you're probably referring to proprietary bank authenticator apps

Yes they do so do quite a few others, but this is about the HSBC authenticator :P

Re: The “Cobra Effect” that is disabling paste on password fields

#259
post #210
post #204

Earlier quoted context omitted.

SSN's in the US are not unique, though they are only used by one person at a time.

"The Social Security Administration does not reuse Social Security numbers" https://en.wikipedia.org/wiki/Social_Security_number#Exhaust...

Well good luck when the keyspace is one billion, and the current population is about a third of that.

Re: The “Cobra Effect” that is disabling paste on password fields

#260
post #204

Earlier quoted context omitted.

SSN's in the US are not unique, though they are only used by one person at a time.

Are you telling me SSN numbers are actually recycled? I don't believe you.

Not reused, but like any system they have made mistakes.

However, there are a few reasons someone will get a new SSN number. Witness protection for example.

Post reply on HN