Live data from Hacker News

Stupid security things

troyhunt.com

121–130 of 161 posts

Re: Stupid security things

#121
post #72

Earlier quoted context omitted.

I don't know if it's a good practice or not, but i usually just pick a word to use for all security questions, that's totally unrelated to the question. ex. I what town did you first meet your best friend? "potato".

This is sorta what I do except I use a unique answer for each one and I store the question and answer in my password manager. Sometimes I use a straight up password generator for the answers. Hope I never have to give those out over the phone.

https://twitter.com/xargsnotbombs/status/858068758379868164

"PRO TIP: To hack the account of a network security engineer, call support and tell them your mother's maiden name is a bunch of hex digits."

Re: Stupid security things

#122
post #97

Why do we still use passwords? When I connect to Amazon.com I don't ask them for a username and password to verify they really are Amazon. I verify their certificate. Why can't I authentic with a certificate too?

Back in the dark, dark days before LetsEncrypt, I had some StartSSL free certs. At one point, I was logging into their site using a certificate. I assume it was quite secure, but it was a complete PITA to set up. Especially when I wanted to log in on a different machine.

Re: Stupid security things

#123
post #115
post #97

Why do we still use passwords? When I connect to Amazon.com I don't ask them for a username and password to verify they really are Amazon. I verify their certificate. Why can't I authentic with a certificate too?

Imagine your grandmother managing her certs. Ain't gonna happen.

Imagine your grandmother managing her passwords

Re: Stupid security things

#124
post #99
post #97

Why do we still use passwords? When I connect to Amazon.com I don't ask them for a username and password to verify they really are Amazon. I verify their certificate. Why can't I authentic with a certificate too?

Because users are more likely to lose a certificate or have it stolen than a website. What happens then?

As compared to losing or forgetting a password?

Re: Stupid security things

#125
post #107

Earlier quoted context omitted.

> This is a totally legit response. Apart from the fact that it is totally untrue?

Who knows if it's untrue? Although it almost certainly is. What's "legit" is the point "lots of other people do it so why should I go to any greater effort? And anyway I don't actually give a shit about my employer's customers." (I was being sarcastic about "legit" -- it's only legit from the selfish POV of the web admin)

Your point is a good one. I think "unfortunate but game-theoretically predictable" would have conveyed it with less confusion.

Re: Stupid security things

#127
post #44

Huh, couple years ago Santander in the UK changed their web layout. No big deal, except that my password wouldn't work anymore - I rang them up, and they said "did you have any special characters in your password? If yes, then they have been removed because the new system does not support special characters. Please use the same password as before, but without special characters". 1) This is one of the largest banks i…

They (as seems to be standard) ask you to enter 3 characters in positions of their choosing, so they need plaintext to be able to do that. It's clearly not as secure as it could be, and it's annoying to work out too - I wish they'd just do normal 2FA. Those plastic keyfobs HSBC use are even worse.

This approach is geared at telephone banking. It means no single employee will learn the entire secret during a call. You generally have a regular password in addition to this step.

Re: Stupid security things

#128

This is pretty horrifying. But almost as bad: websites that insist on over-elaborate security measures for trivial stuff. Take a bow, HM Revenue & Customs: > You’ve got a new message from HMRC > Dear Fred > You have a new message from HMRC about Self Assessment. > To view it, sign in to your HMRC online account. For security reasons, we have not included a link with this email. > Why you got this email > You chose to…

> and hopefully that will be enough for Chrome to autofill it

Doubleclicking text fields or pressing the Down arrow key (with the textbox focused) sometimes produces helpful responses.

If you're just dealing with numbers, though, you only have ten possibilities for the first digit, and actually typing a character is likelier to have higher chances of success.

Re: Stupid security things

#129
post #47

Earlier quoted context omitted.

Yes, they require a signature. I'm not saying this is a safe practice, just that I've never seen a store where they asked me for a pin code for major credit cards such as Visa, Amex and (I'm pretty sure, but I don't have one) MasterCard. And I'm talking not only my own country, but also the US and several countries in Europe. When I was in the UK some years ago, they didn't ask me for my pin code when I used my Visa…

I have both British and Polish debit and credit cards, Visa and Mastercard(Visa Classic credit cards), I've used them in Spain, Germany, Netherlands, France, Spain and Portugal, and literally never had to sign for them, be it in shops or restaurants. I'm not saying there aren't cards that need signing,but I've literally never seen any.

My experience is the opposite: I've never used a PIN.

I've done some reading and now I believe it depends on the country which issued the card (as opposed to the country where you're using the card). So if you have a card issued in the US and Latin America, you probably won't asked for a PIN -- because you don't have one -- and instead you'll be asked for id and your signature. If you have a card issued in Europe, you'll be asked for a PIN.

Interesting. A PIN seems safer than a signature to me, or possibly the combination of chip + PIN, but it simply doesn't get used where I live.

Re: Stupid security things

#130
post #40

That "What is the name of your grandmother's dog?" security question made me lol @ work. This really makes me want to write a "Stupid security questions generator" website.

Why is that funny or bad? If your grandmother is living and has a single dog, as 'security questions' go that would strike me as being pretty good.

It's a bad idea to use anything that might change. For example, "What was the make of your first car?" Might be OK. "What is the make of your favorite car?" Not good, odds are decent your favorite will change between setting the answer and trying to use it.
Post reply on HN