Live data from Hacker News

Stupid security things

troyhunt.com

31–40 of 161 posts

Re: Stupid security things

#31
post #29
post #6

Earlier quoted context omitted.

To be honest credit cards are a terrible system in terms of security. Everything to make a charge is on the card and people freely give it out to different websites.

Is this not changing though? I can't remember the last time I bought something online without having to either use password or 2factor auth, and there are no places here that do not require a pin code when using a cc in a store. I'm in Sweden though (but using mastercard).

Hmmm, that's interesting. I've never been to Sweden, but pretty much no shops in any country I've ever visited required a pin code for Visa or Amex credit cards. Is this really changing?

Re: Stupid security things

#32
post #19

> and I know for a fact 90% of the sites I personally sign up to online also follow that same process. This is a totally legit response. After all if something goes wrong they must have followed "best practices". No reasonable person would expect them to do more. And it's true (if you only consider the needs of the business). This is a solid strategy for getting lawsuits dismissed. I've seen it in physical security t…

1. Are you for or against badge-checking turnstiles? I can't quite say for sure.

2. LCD = lowest common denominator in this case?

Re: Stupid security things

#33
Huh, couple years ago Santander in the UK changed their web layout. No big deal, except that my password wouldn't work anymore - I rang them up, and they said "did you have any special characters in your password? If yes, then they have been removed because the new system does not support special characters. Please use the same password as before, but without special characters".

1) This is one of the largest banks in the UK and they don't accept special characters?

2) If you store my password encrypted(as you should be!), how could you remove any characters from it?

I sent them an official complaint, they replied saying their security is fantastic and there is nothing to worry about, I closed my account a week later.

Re: Stupid security things

#34

This is pretty horrifying. But almost as bad: websites that insist on over-elaborate security measures for trivial stuff. Take a bow, HM Revenue & Customs: > You’ve got a new message from HMRC > Dear Fred > You have a new message from HMRC about Self Assessment. > To view it, sign in to your HMRC online account. For security reasons, we have not included a link with this email. > Why you got this email > You chose to…

One could argue this is actually a good security practice. It's bad to train users that their bank/whoever will be sending them links via email, because then when the user gets a phishing email, they will have no way to tell the difference.

If users can be trained to see "Login to your bank account to see the message", that's much better for their own security.

Re: Stupid security things

#35

This is pretty horrifying. But almost as bad: websites that insist on over-elaborate security measures for trivial stuff. Take a bow, HM Revenue & Customs: > You’ve got a new message from HMRC > Dear Fred > You have a new message from HMRC about Self Assessment. > To view it, sign in to your HMRC online account. For security reasons, we have not included a link with this email. > Why you got this email > You chose to…

I don't get it. It's bad that you have to log in securely to an HMRC portal? I honestly don't see what you're complaining about here.

Re: Stupid security things

#36
post #10

@troyhunt: Have you seen the latest leak by Atlassian? I got an email on 4th April, 2017 that reads as follows: Hello, This weekend, our Security Intelligence Team detected an incident affecting HipChat.com that may have resulted in unauthorized access to user account information (including name, email address and hashed password). Atlassian ID is used to manage access to your HipChat.com account and other Atlassian…

Are you saying that they don't check that the email address you enter is the right one? That would be bad, but I can't see how you can conclude that from the message you quoted.

Re: Stupid security things

#37

This is pretty horrifying. But almost as bad: websites that insist on over-elaborate security measures for trivial stuff. Take a bow, HM Revenue & Customs: > You’ve got a new message from HMRC > Dear Fred > You have a new message from HMRC about Self Assessment. > To view it, sign in to your HMRC online account. For security reasons, we have not included a link with this email. > Why you got this email > You chose to…

I don't get it. It's bad that you have to log in securely to an HMRC portal? I honestly don't see what you're complaining about here.

It's not a message that needs to be delivered securely. It is literally just "you need to fill in your tax return by the same date everyone else in Britain needs to fill in their tax return". That could have been included in the email body with no security implications.

It's basically crying wolf. Next time they have something really important to tell me, I suspect I'll just go "nah, it wasn't important last time, I can't be arsed to spend three minutes logging in" and delete it.

Re: Stupid security things

#38
post #31
post #29

Earlier quoted context omitted.

Is this not changing though? I can't remember the last time I bought something online without having to either use password or 2factor auth, and there are no places here that do not require a pin code when using a cc in a store. I'm in Sweden though (but using mastercard).

Hmmm, that's interesting. I've never been to Sweden, but pretty much no shops in any country I've ever visited required a pin code for Visa or Amex credit cards. Is this really changing?

What do they require then? I've never in my entire life used my credit/debit card without typing in the PIN number(except for contactless payments, of course). I'm in the UK.

I think they can be used with a signature too? Maybe? I've never heard of anyone actually signing a bill instead of using the pin, and besides, I don't even sign my cards.

Re: Stupid security things

#40

That "What is the name of your grandmother's dog?" security question made me lol @ work. This really makes me want to write a "Stupid security questions generator" website.

Why is that funny or bad?

If your grandmother is living and has a single dog, as 'security questions' go that would strike me as being pretty good.

Post reply on HN