Live data from Hacker News

HTTPS on Your Landing Page Is Important

troyhunt.com

241–250 of 307 posts

Re: HTTPS on Your Landing Page Is Important

#241
post #138
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

My citibank credit card redirects me to "cardservicesdirect.com.au" -- which reads like a phishing site if I've ever seen one. I confirmed over the phone with their support that was indeed the correct site before typing anything into it.

My previous mortgage company was a subsidiary of CENLAR. So the corporate branding of the monthly bill listed x&y.com, the actual owner of the company was cenlar.com, and the mortage was paid at loanadministration.com, which until recently had minimal branding even tying it back to cenlar, let alone the company I ostensibly have the direct relationship with.

Re: HTTPS on Your Landing Page Is Important

#242

Earlier quoted context omitted.

Reminiscent of Amex's password policy (at least what it was a few years ago): can't use punctuation in your password, because those keys are less frequently used, and using them frequently in passwords will cause visible wear on the keys, indicating to an attacker with physical access to your keyboard which punctuation characters are in your password. Trying so hard, but failing so badly.

"we require passwords to be a maximum of 8 characters, because if they were longer, people would forget them, and would have to write them down" I'm sure that has been said by some manager somewhere.

Not that it's an excuse, but I've personally seen many "technology averse" people struggle with the changing "rules" about passwords.

When they started using computers, they were taught to NEVER write your password down and to do things like replace letters like I with numbers like 1 for security.

Not only are those not true any more, but the opposite is recommended. Making a unique LONG password is much more important, and writing it down on a sticky note next to your monitor is arguably more secure from some threats than even something like LastPass.

Re: HTTPS on Your Landing Page Is Important

#243

Earlier quoted context omitted.

Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…

Speaking of Microsoft's signin, I can no longer access my decade-old-held Skype since their SSO integration. I've tried over and over and over and tried every route possible. It is some edge case where the email was previously a microsoft account and the password cannot be reset. I'm not the only one with the issue. Shocking something like this doesnt get resolved for years on.

I managed to merge my Skype and Xbox Live accounts, and couldn't get them separated again.

The steps I found to unlink within the XBox UI didn't work, futher research now leads me to the following discussion which I am about to try: https://answers.microsoft.com/en-us/outlook_com/forum/oemail...

Edit: it looks like this was possible in the past (basically deleting the Skype account?), but not anymore.

Re: HTTPS on Your Landing Page Is Important

#244
post #237

A bit side topic: It seems that every time Troy interacts with a company on Twitter, they never seem to click on to who he is, until it's probably too late and they look like fools. It's just so amusing to see companies trying to condescend to Troy, when he's one of the most visible authorities on web security on the planet (not necessarily the most authoritative, but the most well known). I occasionally get this whe…

>It seems that every time Troy interacts with a company on Twitter, they never seem to click on to who he is, until it's probably too late and they look like fools. On the other hand, Troy is looking like a fool for trying to argue about security with a girl intern that works with social media and has no clue about netsec. Every one of his posts and threads on Twitter are "let's bully this poor intern". He's fucking…

[deleted]

Re: HTTPS on Your Landing Page Is Important

#245
post #149
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

One of the worst I've seen is Franklin Templeton. They sent out snail mail telling everyone to go to a URL like "accountservices.biz" and reenter private information like your social security number in order to update your account records. The site itself is branded just like Templeton's own site. From what I could gather, it is actually their site but even the whois is something non descript. Quite ridiculous. And o…

That would be a fascinating way to do a scam. Send snail mail to people directing them to a site that looks like a major company, ask them to enter in their PII and boom, there you go. Of course now you've committed untold amounts of federal crime by using the postal system and you'd definitely get sent to federal PMITA prison if you got caught. But I could definitely see this working on older people who, bless their little hearts, just don't know any better.

Re: HTTPS on Your Landing Page Is Important

#246
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

Microsoft's login experience has been generally broken for years. Multiple redirects through different domains. Heck it uses Javascript redirects. In 2017. So your back button won't work. And it has a habit of just not working. I went to visit a public page on docs.microsoft.com and wound up dead on a white page on login.live.com because it decided I needed to be redirected to login. Just to view a docs page.

What is the alternative to javascript redirecting when you can't do it as the http response?

Re: HTTPS on Your Landing Page Is Important

#247

It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.

Guess what! If your financial service restricts your password to letters and numbers, it's most likely because they want you to be able to enter your password on the phone. So the passwords 'abc' 'ABC' and '222' are treated as equivalent. Try it out for fun!

Source?

Re: HTTPS on Your Landing Page Is Important

#248

It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.

BMO in Canada forces 6 digits or alphanumerics as your account password. No more, no less. What's worse, because it can be entered on the phone, aAbBcC are all == 1. So it's really just 6 digits.

It just took my terrible python program 9 seconds to guess 999999.

Re: HTTPS on Your Landing Page Is Important

#249

Earlier quoted context omitted.

BMO in Canada forces 6 digits or alphanumerics as your account password. No more, no less. What's worse, because it can be entered on the phone, aAbBcC are all == 1. So it's really just 6 digits.

Somewhere, in the background, there's a poor old unix mainframe running Cobol, unaware that the world around it has changed, and that it should put to pasture, where it can live out the rest of its days in peace.

"Unix mainframe" is something that never really existed, mainframes run special operating systems like z/OS. (You can run SuSE on a virtual partition under z, but not natively, and it is a recent concept.)

Re: HTTPS on Your Landing Page Is Important

#250
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

Microsoft's login experience has been generally broken for years. Multiple redirects through different domains. Heck it uses Javascript redirects. In 2017. So your back button won't work. And it has a habit of just not working. I went to visit a public page on docs.microsoft.com and wound up dead on a white page on login.live.com because it decided I needed to be redirected to login. Just to view a docs page.

I don't know if this is still the case, but you couldn't login if you had 3rd party cookies disabled. Somewhere in the authentication phase, it would silently fail. No error message like incorrect username/password. You'd get kicked back to the login screen as if you just got there. It was a hassle trying to find exactly which cookies were necessary.
Post reply on HN