it-doesnt-matter-because-that-isnt-the-point.com
What is the point?
(Banks should also protect against easily phishable domain names but that's a also losing game, and in that case the technical solution is not as simple or complete).
291–300 of 307 posts
it-doesnt-matter-because-that-isnt-the-point.com
What is the point?
(Banks should also protect against easily phishable domain names but that's a also losing game, and in that case the technical solution is not as simple or complete).
Earlier quoted context omitted.
Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…
Speaking of Microsoft's signin, I can no longer access my decade-old-held Skype since their SSO integration. I've tried over and over and over and tried every route possible. It is some edge case where the email was previously a microsoft account and the password cannot be reset. I'm not the only one with the issue. Shocking something like this doesnt get resolved for years on.
[1] https://support.microsoft.com/en-us/help/12412/microsoft-acc...
Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…
Earlier quoted context omitted.
T-Mobile called me back one time instead of me waiting on hold. This was after I went through the song and dance of giving the automated system my details. The first thing this representative wanted to do was, again, confirm I am who I said I was. I said think about what you're asking for a second. Should I answer your questions? Couldn't get them to understand. Wound up hanging up and calling again and waiting on ho…
My bank actually gets this right. They very, very rarely call me, but when they do it's "Hello, am I talking to Nick Lamb?" "Yes, this is me" "OK, I'm calling from Example Bank and our confirmatory password is Melons" [not the actual bank or password] "Thanks, that checks out, what can I do for you?" This happened because I had one of those conversations you're talking about, and they were like "Aha! We have somethin…
Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…
Microsoft's login experience has been generally broken for years. Multiple redirects through different domains. Heck it uses Javascript redirects. In 2017. So your back button won't work. And it has a habit of just not working. I went to visit a public page on docs.microsoft.com and wound up dead on a white page on login.live.com because it decided I needed to be redirected to login. Just to view a docs page.
Earlier quoted context omitted.
Words are hard. Anyone got an idea for a better word? Send your ideas to the security-dev mailing list (at least, I think that's the best forum...): https://groups.google.com/a/chromium.org/forum/#!forum/secur...
Perhaps the reverse would be better. If a site doesn't use HTTPS, call it unsecured.
Google specifically says (without naming a date) that their long term intent is to put a UI like a red triangle plus the phrase "Not Secure" in the URL bar for all HTTP sites on their desktop browser. This is the same treatment you get today for a site with a bogus SSL certificate and similar to the treatment HTTP sites get now in Incognito mode.
A bit side topic: It seems that every time Troy interacts with a company on Twitter, they never seem to click on to who he is, until it's probably too late and they look like fools. It's just so amusing to see companies trying to condescend to Troy, when he's one of the most visible authorities on web security on the planet (not necessarily the most authoritative, but the most well known). I occasionally get this whe…
Earlier quoted context omitted.
The funny thing is, checking their web site they still haven't managed to secure their landing page. You'd think they'd get the message when everyone's just laughing at them...
To play devil's advocate: everyone = Hacker News Mostly likely not their customers; whom they have a vested interest in keeping money with.
My care factor is probably very different to most non techies, by assumption. Then again, there's probably a bunch of things I do that would annoy(?) {them} greatly - that I'm not even aware of.
Probably not a good person to piss off. Several months ago I recall a website owner posted a bug to Firefox saying he didn’t need HTTPs and that Firefox shouldn’t tell users it’s insecure. Within hours his database was pwned.
Are you suggesting that Troy Hunt is involved in illegal pentesting ( pwning their db )? I really doubt that. He is an industry professional. The problem is not pissing off Troy Hunt; but more that they are advertising that their website is vulnerable and that they don't care.
Earlier quoted context omitted.
And it's so easy for anyone nowadays to get SSL with Let's Encrypt... I remember a few years ago when there was no way you could do it for side projects because certs were 100/yr., now they're free.
It is not easy if you are on a shared domain and it is not supported by your host. Please don't run around saying it is easy for everyone.