Live data from Hacker News

Stupid security things

troyhunt.com

151–160 of 161 posts

Re: Stupid security things

#151
post #144
post #18

Earlier quoted context omitted.

They have their email and their ID, added with the knowledge they are compromised. That's enough to build a spoof password reset email and get them to type in an old/new email.

Oh no! someone could send me an email confirming that I want to reset my password! Just like every other site out there that has a forgot password link.

They know their email and ID - so it's targeted. Without this information it is generic and easily spotted. Quoting your repository is a lot more personal and believable.

Additionally you can use the previous warning emails to really target somebody as one of the few that need "further recovery/security" steps. This is a security issue.

Re: Stupid security things

#152
post #10

@troyhunt: Have you seen the latest leak by Atlassian? I got an email on 4th April, 2017 that reads as follows: Hello, This weekend, our Security Intelligence Team detected an incident affecting HipChat.com that may have resulted in unauthorized access to user account information (including name, email address and hashed password). Atlassian ID is used to manage access to your HipChat.com account and other Atlassian…

Are you saying that they don't check that the email address you enter is the right one? That would be bad, but I can't see how you can conclude that from the message you quoted.

I'm not saying that at all?

Re: Stupid security things

#153
post #48
post #10

@troyhunt: Have you seen the latest leak by Atlassian? I got an email on 4th April, 2017 that reads as follows: Hello, This weekend, our Security Intelligence Team detected an incident affecting HipChat.com that may have resulted in unauthorized access to user account information (including name, email address and hashed password). Atlassian ID is used to manage access to your HipChat.com account and other Atlassian…

I am not using HipChat but I am using Trello and now that they have been acquired by Atlassian I wonder if they linked all of Trello's accounts to an Atlassian ID? As an added precaution, we have reset your Atlassian ID which is used to access all Atlassian services

Possibly, it's worth resetting to step on the side of caution. Good to occasionally rotate your passwords anyway!

Re: Stupid security things

#154
post #58
post #10

@troyhunt: Have you seen the latest leak by Atlassian? I got an email on 4th April, 2017 that reads as follows: Hello, This weekend, our Security Intelligence Team detected an incident affecting HipChat.com that may have resulted in unauthorized access to user account information (including name, email address and hashed password). Atlassian ID is used to manage access to your HipChat.com account and other Atlassian…

He has. https://twitter.com/troyhunt/status/856603660737945601

Didn't see this, thanks.

I didn't get an email from the email checking website - I assume they haven't disclosed a database of emails with him.

Re: Stupid security things

#155
If there’s one thing that needs to go away ASAP, it’s “security” questions. They are so time-consuming, they increase the amount of information shared with 3rd parties, and the quotes I used are intentional because the questions provide no security whatsoever. Quite the opposite: these questions simply force people to share more information than they should be required to share, and (for most people who don’t think to lie) it increases the chance that sensitive secrets will be revealed and used to impersonate people.

It’s even worse when these “security” questions are coupled with the “Monday-Friday, 9-5 ET” phone numbers. I once had a mobile login “lock out my account” on a Friday night and I was informed that I could not unlock it without calling one of those numbers and answering my “security” questions. So instead of having access as a customer, I had over two full days of nothing, followed by the obligation to find time to call these people, followed by the awkward process of wondering if I would even remember the damned questions or answers. Every last bit of that process is broken, wrong, unnecessary, adds no security, and disrespects customers.

And in case you think account-lockouts are any better, consider that it is TRIVIAL to use this as an attack. Someone you don’t like? Odds are you can find their E-mail log-in. “Guess” their password 3 times, and they can’t access their account at all for some extremely-inconvenient length of time. Ever-increasing delays between log-in attempts work just fine as an alternative to lockouts.

Re: Stupid security things

#156
post #34

Earlier quoted context omitted.

One could argue this is actually a good security practice. It's bad to train users that their bank/whoever will be sending them links via email, because then when the user gets a phishing email, they will have no way to tell the difference. If users can be trained to see "Login to your bank account to see the message", that's much better for their own security.

Then they go to google and click the first link... that will be a paid ad to a phishing site.

More likely: they click on the link right after that, which is part of the phishing scam.

Re: Stupid security things

#157
post #125
post #107

Earlier quoted context omitted.

Who knows if it's untrue? Although it almost certainly is. What's "legit" is the point "lots of other people do it so why should I go to any greater effort? And anyway I don't actually give a shit about my employer's customers." (I was being sarcastic about "legit" -- it's only legit from the selfish POV of the web admin)

Your point is a good one. I think "unfortunate but game-theoretically predictable" would have conveyed it with less confusion.

Sorry, I grew up in a culture in which being so explicit was rude, while being barely-elliptically witty is the normal mode of discourse. I sometimes forget.

Re: Stupid security things

#158
post #44

Earlier quoted context omitted.

They (as seems to be standard) ask you to enter 3 characters in positions of their choosing, so they need plaintext to be able to do that. It's clearly not as secure as it could be, and it's annoying to work out too - I wish they'd just do normal 2FA. Those plastic keyfobs HSBC use are even worse.

This approach is geared at telephone banking. It means no single employee will learn the entire secret during a call. You generally have a regular password in addition to this step.

Why can't I tell a bank employee a time-based 2FA code over the telephone?

Re: Stupid security things

#159
post #106
post #32

Earlier quoted context omitted.

1. Are you for or against badge-checking turnstiles? I can't quite say for sure. 2. LCD = lowest common denominator in this case?

2. indeed. 1. I don't really give a shit either way when I encounter one but as a businessman I am against them as something I should have to pay for. My points were twofold: A> there's a games theory/cartel issue around "best practices", and you basically have no liability if you provide the "standard of care". This is true in security practices, medicine, etc. And B> there is often an incentive mismatch between the…

With regards to your point B, I'm happy to remove my shoes if it reduces my chances of being killed in a terror attack from (making up numbers) 1/1M to 1/1.05M. It's just that it's unclear whether the TSA's screening methods are effective, and/or optimally-effective, and/or optimally-effective while minimizing passenger inconvenience. (They're probably at least somewhat effective, at least as a psychological deterrent, seeing as there hasn't been a successful terror attack on a US airplane since 9/11).

Re: Stupid security things

#160
post #106

Earlier quoted context omitted.

2. indeed. 1. I don't really give a shit either way when I encounter one but as a businessman I am against them as something I should have to pay for. My points were twofold: A> there's a games theory/cartel issue around "best practices", and you basically have no liability if you provide the "standard of care". This is true in security practices, medicine, etc. And B> there is often an incentive mismatch between the…

With regards to your point B, I'm happy to remove my shoes if it reduces my chances of being killed in a terror attack from (making up numbers) 1/1M to 1/1.05M. It's just that it's unclear whether the TSA's screening methods are effective, and/or optimally-effective, and/or optimally-effective while minimizing passenger inconvenience. (They're probably at least somewhat effective, at least as a psychological deterren…

Correlation does not equal causation. There also have been no successful terror attacks on a US airplane since they 1) Implemented reinforced cockpit doors, 2) stopped allowing people to line up for the forward bathroom, 3) added air marshals to the planes, 4) implemented TSA pre-check.

So we have no idea, if any of these, has actually improved security. It's possible that just no one has tried since 9/11 because there was no reason to.

Post reply on HN