Live data from Hacker News

Don't give away historic details about yourself

krebsonsecurity.com

151–160 of 207 posts

Re: Don't give away historic details about yourself

#152
post #135
post #98

Earlier quoted context omitted.

I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.

Yesterday, I was logging onto Australian MyGov site, and forgot the password, it sent SMS code for reset to my mobile phone, but then would not let me proceed without answering the secret questions. I usually put last word of the question sentence as an answer itself because I can't be bothered, but it was not the case this time. Not a great experience when they threaten lock out of account, and you have to go link a…

MyGov is a dumpster fire of bad choices.

Some of it is legacy - integrating systems built throughout the last three decades.

Some of it is management - they fired multiple teams partway through, with 100% turnover. They also massively underfunded said teams, devoting the majority of funding to PR. Also some... Interesting technical policies, like banning version control and advocating regular backups instead. (Something to do with code "theft protection").

Some of it was technical issues - different integration teams were given different browser compatibility goals. Some teams were told they must use PHP and Apache, others they must use NodeJS and nginx. Often for related parts of the UI.

If you want to know how to screw up a multi-million dollar project, look no farther.

(Source: Worked with a team leader during one of the "fire everyone" times.)

Re: Don't give away historic details about yourself

#153
post #57
post #15

Earlier quoted context omitted.

SMS-based 2FA should be avoided as much as possible, since there are many ways to take over a phone number and get a hold of the code. Passwords, while being a huge hassle, is probably going to be the defacto authentication mechanism for sites and services (unfortunately). Maybe some sort of distributed PKI authentication + 2FA combo would be an interesting solution, but the problem would be adoption.

Doesn’t 2fa mean password + phone? How is getting the phone sufficient?

You can often reset the password if you can intercept the chosen token generator, like SMS.

Re: Don't give away historic details about yourself

#154

I use 1Password as a password vault. Some years ago, I decided to start lying for secret question answer challenges. I use 1Password to generate a string of garbage (without numbers or symbols, 25 characters long) and keep that answer in a custom field in the 1Password vault. I've tagged those entries with a security tag to find all accounts with secret Q&A information. I am paranoid about back ups because if god for…

One problem with this is social engineering... someone could call the company to recover their password and say that they entered garbage for the security question... I started to enter passphrases instead

Good point. I’ll have to think it over a bit. Since I have all the info should be very easy to fix up the data. Just time consuming

Re: Don't give away historic details about yourself

#155
post #124

Earlier quoted context omitted.

SMS can also be captured by calling the customer service for your cell company and saying "I'm out of the country and lost my phone, can you forward texts to INSERT NUMBER HERE for me?"

use a burner sim like: https://www.twilio.com/wireless/pricing . presumably twillio is harder to social engineer than [big telecom]

The Twilio SIM card is not as useful as you might expect. Unfortunately, Twilio cannot receive SMS messages from short codes [1], which are often used used by the kinds of places (banks etc) that rely on SMS for 2FA.

Also, keep in mind that an adversary can grab your text messages even without any social engineering skills; they just need to rent a cell tower somewhere in the world and advertise your number as roaming there [2]

As you implied, it is probably safer to use a different number than your main one for SMS-based 2FA (the much-maligned security through obscurity), but before you go out and buy a second phone plan, consider issues such as whether you will be able to receive SMS messages while traveling internationally.

[1] https://support.twilio.com/hc/en-us/articles/223181668-Can-T...

[2] https://news.ycombinator.com/item?id=16773171

Re: Don't give away historic details about yourself

#156
post #15

Earlier quoted context omitted.

SMS-based 2FA should be avoided as much as possible, since there are many ways to take over a phone number and get a hold of the code. Passwords, while being a huge hassle, is probably going to be the defacto authentication mechanism for sites and services (unfortunately). Maybe some sort of distributed PKI authentication + 2FA combo would be an interesting solution, but the problem would be adoption.

In fact this is a method of stealing people's investment accounts -- a victim with an investment account is identified. That person's phone number is then "captured". The investment account asks for 2FA and the thief now has that phone #, and "authenticates." The next step is to transfer all the money in the account to a third party and disappear. It's disgusting how twisted these criminal activities have become.

How does the phone number get identified? You would think that'd be confidential.

Re: Don't give away historic details about yourself

#157
post #97
post #61

Earlier quoted context omitted.

I agree with you and for accounts that matter (bank, etc), I'll generally generate additional passwords with my PW manager for each question and store them there. That said, I have a peeve with one of the standard questions they ask, which is the "favorite" question. Favorite movie, favorite band, favorite song, etc. Besides the fact that I don't have One Favorite anything, does anyone actually have life-long singula…

The ones I love are those with questions like "What was the first city you visited" and they give you a multiple choice of like ten cities, none of which you may ever actually have visited.

[deleted]

Re: Don't give away historic details about yourself

#158
post #120
post #98

Earlier quoted context omitted.

I used to answer secret questions with bogus answers that I deemed unguessable. Then I discovered that when my bank asks me the questions back it does multiple choice, displaying the answer I gave along with 4 other possible options! Sometimes my answer would not be shown and the correct answer is "none of the above", but otherwise my answer sticks out like a sore thumb.

This, too, was my problem. I don't want to give out real answers to my security question for two (slightly contradictory) reasons. The first is: what if this site is hacked? Now my security question answers are floating around for use on other sites that ask similar questions. The second is: some of these questions are pretty easy to find the answer to, or guess. So I used a generated string for those questions, too.…

I have a third problem -- often times, the list of questions they ask are non-sense to me. "What is your favorite food?" I don't have a favorite, and can't think of anything that I'd remember later. "What was the name of your first pet?" I never had a pet. "What was the name of your high school sweetheart?" Gee, thanks a lot for stirring up bad memories.

Re: Don't give away historic details about yourself

#159
post #17

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

I agree, secret questions are dumb... but what are the alternatives? The majority of human beings now manage important parts of their lives online, which means they have to remember passwords. Humans are TERRIBLE at remembering passwords - those of us who use a password manager represent a fraction of a percent of those who need one. Secret questions may be revoltingly insecure, but they do at least let people get ba…

I'd love the option to at least use Touch ID. Facebook is a huge example. I have a long complicated password, and when I switch Messenger accounts, it likes to ask for it. Why can't I just use my thumbprint and Touch ID? Same with Barclays. The app wants my password 2/3 of the time, even though I have it set to use Touch ID.

I'd at least like the option to use Touch ID/Face ID only.

Re: Don't give away historic details about yourself

#160

The whole "secret question" thing seemed to me to a completely stupid idea from the start. "Hey, give us password. If you forget your password, give us a much, much less secure way to access your account." I've always given false info to those, when I bother to fill them out at all. If necessary, I just store this false info along with the password in the encrypted file I keep my passwords in. The security questions…

What's worse these days is, ever since the Equifax breach, certain institutions have taken to asking me for the last 6 digits of my social (or even worse... all of them...)

SSN isn't even a 'secret' number. Military folk have it on their ID tags and you're supposed to give it up if you're a POW. If you're supposed to give it to your enemies, then how is it private info?
Post reply on HN