Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…
My citibank credit card redirects me to "cardservicesdirect.com.au" -- which reads like a phishing site if I've ever seen one. I confirmed over the phone with their support that was indeed the correct site before typing anything into it.
HTTPS on Your Landing Page Is Important
241–250 of 307 posts
Re: HTTPS on Your Landing Page Is Important
#242Earlier quoted context omitted.
Reminiscent of Amex's password policy (at least what it was a few years ago): can't use punctuation in your password, because those keys are less frequently used, and using them frequently in passwords will cause visible wear on the keys, indicating to an attacker with physical access to your keyboard which punctuation characters are in your password. Trying so hard, but failing so badly.
"we require passwords to be a maximum of 8 characters, because if they were longer, people would forget them, and would have to write them down" I'm sure that has been said by some manager somewhere.
When they started using computers, they were taught to NEVER write your password down and to do things like replace letters like I with numbers like 1 for security.
Not only are those not true any more, but the opposite is recommended. Making a unique LONG password is much more important, and writing it down on a sticky note next to your monitor is arguably more secure from some threats than even something like LastPass.
Re: HTTPS on Your Landing Page Is Important
#243Earlier quoted context omitted.
Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…
Speaking of Microsoft's signin, I can no longer access my decade-old-held Skype since their SSO integration. I've tried over and over and over and tried every route possible. It is some edge case where the email was previously a microsoft account and the password cannot be reset. I'm not the only one with the issue. Shocking something like this doesnt get resolved for years on.
The steps I found to unlink within the XBox UI didn't work, futher research now leads me to the following discussion which I am about to try: https://answers.microsoft.com/en-us/outlook_com/forum/oemail...
Edit: it looks like this was possible in the past (basically deleting the Skype account?), but not anymore.
Re: HTTPS on Your Landing Page Is Important
#244A bit side topic: It seems that every time Troy interacts with a company on Twitter, they never seem to click on to who he is, until it's probably too late and they look like fools. It's just so amusing to see companies trying to condescend to Troy, when he's one of the most visible authorities on web security on the planet (not necessarily the most authoritative, but the most well known). I occasionally get this whe…
>It seems that every time Troy interacts with a company on Twitter, they never seem to click on to who he is, until it's probably too late and they look like fools. On the other hand, Troy is looking like a fool for trying to argue about security with a girl intern that works with social media and has no clue about netsec. Every one of his posts and threads on Twitter are "let's bully this poor intern". He's fucking…
Re: HTTPS on Your Landing Page Is Important
#245Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…
One of the worst I've seen is Franklin Templeton. They sent out snail mail telling everyone to go to a URL like "accountservices.biz" and reenter private information like your social security number in order to update your account records. The site itself is branded just like Templeton's own site. From what I could gather, it is actually their site but even the whois is something non descript. Quite ridiculous. And o…
Re: HTTPS on Your Landing Page Is Important
#246Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…
Microsoft's login experience has been generally broken for years. Multiple redirects through different domains. Heck it uses Javascript redirects. In 2017. So your back button won't work. And it has a habit of just not working. I went to visit a public page on docs.microsoft.com and wound up dead on a white page on login.live.com because it decided I needed to be redirected to login. Just to view a docs page.
Re: HTTPS on Your Landing Page Is Important
#247It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.
Guess what! If your financial service restricts your password to letters and numbers, it's most likely because they want you to be able to enter your password on the phone. So the passwords 'abc' 'ABC' and '222' are treated as equivalent. Try it out for fun!
Re: HTTPS on Your Landing Page Is Important
#248It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.
BMO in Canada forces 6 digits or alphanumerics as your account password. No more, no less. What's worse, because it can be entered on the phone, aAbBcC are all == 1. So it's really just 6 digits.
Re: HTTPS on Your Landing Page Is Important
#249Earlier quoted context omitted.
BMO in Canada forces 6 digits or alphanumerics as your account password. No more, no less. What's worse, because it can be entered on the phone, aAbBcC are all == 1. So it's really just 6 digits.
Somewhere, in the background, there's a poor old unix mainframe running Cobol, unaware that the world around it has changed, and that it should put to pasture, where it can live out the rest of its days in peace.
Re: HTTPS on Your Landing Page Is Important
#250Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…
Microsoft's login experience has been generally broken for years. Multiple redirects through different domains. Heck it uses Javascript redirects. In 2017. So your back button won't work. And it has a habit of just not working. I went to visit a public page on docs.microsoft.com and wound up dead on a white page on login.live.com because it decided I needed to be redirected to login. Just to view a docs page.