Live data from Hacker News

Bypassing Browser Security Warnings with Pseudo Password Fields

troyhunt.com

11–20 of 127 posts

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#11

Earlier quoted context omitted.

I'm assuming you're talking about consumer VoIP; in the corporate world, Cisco (and presumably others) do a crapload of VoIP office phones.

I also haven't seen an office phone in ages, it's just all mobiles around here.

It's because you don't do bulk calls. Sells, support, orders, etc. They all need office phones at a certain scale. Not that they couldn't do it with mobiles. But infrastructures for those kind of systems all assume a land line.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#12

Earlier quoted context omitted.

I'm assuming you're talking about consumer VoIP; in the corporate world, Cisco (and presumably others) do a crapload of VoIP office phones.

I also haven't seen an office phone in ages, it's just all mobiles around here.

I've worked for pretty much every type of company except VC-funded Silicon Valley style start-ups since about 2008. Every desk I've ever sat at, including the one I'm at now, has had a VoIP phone sitting on it.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#13

If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data. HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this w…

In my experience, the entire world runs on insecure systems (and will continue to do so until companies start getting sued into oblivion for leaking data). Secure systems are the exception--not the norm. It's just not a priority because companies only prioritize things that "add value". So until we attach a real cost to lack-of-security, it won't be valued.

I've literally seen a college have admin credentials hosted on a publicly addressable plaintext document just so that their new machines can netboot. And that's just one, quick, story out of dozens upon dozens I have.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#15

Earlier quoted context omitted.

I also haven't seen an office phone in ages, it's just all mobiles around here.

It's because you don't do bulk calls. Sells, support, orders, etc. They all need office phones at a certain scale. Not that they couldn't do it with mobiles. But infrastructures for those kind of systems all assume a land line.

Decent deskphones are significantly more comfortable than cellphones, nevermind the better audio hardware.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#16

If only we had these kinds of strong warnings in the VOIP industry. Nearly every provider barebacks the internet, throwing unencrypted signaling data (phone number dialed, keys pressed during the call, codec to use) and call media over the internet raw, just hoping that no one eavesdrops or alters their data. HIPPA compliance? Nah bruh, unencrypted UDP is just fine! PCI-DSS says we can't take credit cards over this w…

In my experience, the entire world runs on insecure systems (and will continue to do so until companies start getting sued into oblivion for leaking data). Secure systems are the exception--not the norm. It's just not a priority because companies only prioritize things that "add value". So until we attach a real cost to lack-of-security, it won't be valued. I've literally seen a college have admin credentials hosted…

Admins are lazy and busy, hence why UW for example runs a totally insecure PBX, which is surprising considering Avaya is usually one of the better vendors.

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#17
post #12

Earlier quoted context omitted.

I also haven't seen an office phone in ages, it's just all mobiles around here.

I've worked for pretty much every type of company except VC-funded Silicon Valley style start-ups since about 2008. Every desk I've ever sat at, including the one I'm at now, has had a VoIP phone sitting on it.

In the early days at Nest, one of my co-workers had trouble with his loan application because Nest, his employer, didn’t have a phone number. He showed the bank the company’s web site, and they were satisfied. Only a real company would have an actual web site.

For added fun, the site looked like this at the time https://web.archive.org/web/20110207225932/http://nestlabs.c...

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#18
post #14

Surely it would be easier to just get a cert. What's preventing these types from doing so?

What's easier for a dev: inserting a few lines of code, or getting access to the production server, setting up letsencrypt (or getting a budget approval for the $10/year certificate)?

Re: Bypassing Browser Security Warnings with Pseudo Password Fields

#19
post #14

Surely it would be easier to just get a cert. What's preventing these types from doing so?

I believe it's either (a) a lack of understanding of _why_ one should use SSL or (b) a mistaken sense of principle of standing up to the perceived bulliness of Google, which, come to think of it, it's basically an application of (a)
Post reply on HN