Live data from Hacker News

Stupid security things

troyhunt.com

141–150 of 161 posts

Re: Stupid security things

#141

Wow, that might be the worst I've ever seen. Does anyone here buy from auction sites often? Those are a nightmare, they let the sellers do pretty much anything and very few accept paypal (they're THAT stingy) - sellers on liveauction.com routinely ask buyers to provide credit card info over email. It looks like a lot of sellers are flocking to these because ebay is too strict, wait, I mean "sane".

Recently I won an auction at Galabid.com. They use Stripe and after putting my credit card, it was denied (I think because it was a large payment and I have no limits). Unfortunately, the Stripe JS popup didn't let me change the card. I don't know why - I tried incognito, diff browsers, but it was helpless. I had to send another Card number and all its data through email or the items were going to be auctioned again…

Our tollway providers site

    * inactivates your account if your account is negative.
    * one reason for negative account is the credit card is expired.
    * you cannot update your credit card if the account is inactive.

Re: Stupid security things

#142
post #72

Earlier quoted context omitted.

I don't know if it's a good practice or not, but i usually just pick a word to use for all security questions, that's totally unrelated to the question. ex. I what town did you first meet your best friend? "potato".

Don't do that unless you don't care about that account. Often the answer to a security question effectively acts as a password. You are not defending against someone guessing your answer, you are defending against someone using an automated dictionary attack. A common word like 'potato' scores quite high in the common password lists. A safer option is to just generate a random password for those questions as well and…

If you do that then it's super easy to social engineer the company in question. "I don't know what I put for mother's maiden name, I just mashed the keys a lot on that".

Re: Stupid security things

#143
post #74

Earlier quoted context omitted.

I like the plastic keyfobs. They're much more secure than using your phone as 2FA. Basically the only thing keeping HSBC/1st direct secure.

How are they more secure than your phone? If by phone you mean SMS, then I agree. But as far as I understand, TOTP (ie Google Authenticator) is pretty secure. But I'm not a security expert.

The plastic key fob is totally isolated from any network. If your phone was isolated like this you would need a new phone. Google Authenticator can be cloned if you compromise the device. A plastic key fob that has no input is for all practical purposes impossible to clone and if it's stolen it can be easily revoked.

Re: Stupid security things

#144
post #18

Earlier quoted context omitted.

No, they couldn't have gotten people's passwords. They could have their passwords _encrypted with a random salt_. Which is, frankly, useless.

They have their email and their ID, added with the knowledge they are compromised. That's enough to build a spoof password reset email and get them to type in an old/new email.

Oh no! someone could send me an email confirming that I want to reset my password! Just like every other site out there that has a forgot password link.

Re: Stupid security things

#145
post #82
post #69

This is a huge problem and has been for a long time. We allow pretty much anyone to code up a website. It'd be similar to allowing anybody to start practicing medicine. I've lost count of how many websites I've used that were blatantly insecure. Sometimes you have no choice but to do it, like when I had to apply for a Brazil travel visa. Their SSL certificate has expired, and has been expired for years now.

So you'd rather the government hand out certifications and only allow those certified people to create websites? That sounds better.

There would be benefits to licensing web dev. I wouldn't suggest that a license should be required for any web development but if the website is used to safeguard PII or secure financial transactions then I don't think it would be too unreasonable to do so to get rid of these clowns. I used to work in an SMB web development shop and the incompetence that I'd see daily from our competition really changed my perspective on the field.

I used to feel almost like an imposter when I first started but I've seen so many "experts" who have been selling their services for decades yet they don't understand even the fundamentals of their profession. We already require licensing professionals for many things which are arguably less important than a lot of websites. I think a fair balance could be struck here to make sure that large businesses like Betfair can't get away with this crap yet not stifle hobbyists or businesses whose websites don't pose any appreciable risk.

Re: Stupid security things

#146
post #74

Earlier quoted context omitted.

I like the plastic keyfobs. They're much more secure than using your phone as 2FA. Basically the only thing keeping HSBC/1st direct secure.

How are they more secure than your phone? If by phone you mean SMS, then I agree. But as far as I understand, TOTP (ie Google Authenticator) is pretty secure. But I'm not a security expert.

This is getting into very marginal territory, but attack surface. Your phone is an entire network-capable OS with god-knows what security vulns or backdoors. Those dongles are an air-gapped, often tamper-resistant chip.

For the record, I think services should ideally offer all three options (SMS, TOTP and physical device), since the biggest problem in security is actually getting users to use ANYTHING at all, and something like SMS that offers 99% of the protection in return for easier setup/ease of use is well worth it.

Re: Stupid security things

#147
post #81

This reminds me of AT&To Gophone website. Your username is your phone number and your password is a 4 digit PIN. The same pin you can use to transfer out your number.

this is exactly why 2FA with SMS is not secure at all. If someone really wants to get into your account all you have done is added one extra step where they need to steal your phone account and then they steal your other account. It has been shown how easy it is to steal someones phone account and transfer the number to a cheap burner phone or online service. This also kills your cell service so unless you have anoth…

> is not secure at all

Absolutes are the wrong language. It adds a significant burden (steal the user's phone account), which if nothing else requires individual attention, which drastically changes the economics of an attack vs, say, mass automated attacks using leaked passwords checking for re-use. Sure, you and I might have unique randomly generated passwords for our accounts, but not everyone is so careful, and SMS verification can and does save many an account.

Re: Stupid security things

#148
If you contacted Rackspace's chat support while logged in, the representative sometimes asked the security question. To which (remember, you're logged in) you could click "Account Settings", "Security Question" copy paste.

A former employer of mine had internal security questions. Five of them. They were all inane questions, the "favorite movie?" type, so I came up with a somewhat random answer and used the same answer to all of them. The one time I had to use it, the representative asked all five questions, and I gave him the same ridiculous answer each time. He did it all with a straight face somehow, and looking back, I don't know why I didn't stop him at the fourth question to ask "if I knew the first three, you really think I don't know the last two?"

Re: Stupid security things

#149
post #142

Earlier quoted context omitted.

Don't do that unless you don't care about that account. Often the answer to a security question effectively acts as a password. You are not defending against someone guessing your answer, you are defending against someone using an automated dictionary attack. A common word like 'potato' scores quite high in the common password lists. A safer option is to just generate a random password for those questions as well and…

If you do that then it's super easy to social engineer the company in question. "I don't know what I put for mother's maiden name, I just mashed the keys a lot on that".

Apple does not allow. If u forgot your security questions you cannot add 2FA

Re: Stupid security things

#150

This is pretty horrifying. But almost as bad: websites that insist on over-elaborate security measures for trivial stuff. Take a bow, HM Revenue & Customs: > You’ve got a new message from HMRC > Dear Fred > You have a new message from HMRC about Self Assessment. > To view it, sign in to your HMRC online account. For security reasons, we have not included a link with this email. > Why you got this email > You chose to…

People elsewhere in the world: whatever anybody tells you when they're crapping on the UK Government Digital Service, make sure they're not using HMRC as an example. Famously HMRC resists everything GDS has ever tried to do, and after GDS built a entire system for secure gov ID login which is deliberately not tied to a single vendor, HMRC refused to use it and instead is building another one, which is locked to a sin…

Ok, I'll take your word for it, but that said HMRC is the only way in which I ever interact with the Government online.

If GDS can't get their claws into HMRC then Government digital (lower case) is pretty broken.

Post reply on HN