Live data from Hacker News

Congressman's phone password is 111111

gfycat.com

1–10 of 206 posts

Re: Congressman's phone password is 111111

#3
That is a iPhone X like device, which only has Face ID or a PIN.

A PIN is more secure than a fingerprint and Face ID. But at least use a combination of either one with a PIN to make it more secure.

Since the device was already on and it directly showed the PIN screen, Face ID is disabled and instead he chooses to only use a very very weak PIN.

Oh dear.

Re: Congressman's phone password is 111111

#4
post #3

That is a iPhone X like device, which only has Face ID or a PIN. A PIN is more secure than a fingerprint and Face ID. But at least use a combination of either one with a PIN to make it more secure. Since the device was already on and it directly showed the PIN screen, Face ID is disabled and instead he chooses to only use a very very weak PIN. Oh dear.

> A PIN is more secure than a fingerprint and Face ID...

While generally true, this is probably not the case for someone who's regularly using their phone on camera like a Congressional rep.

Re: Congressman's phone password is 111111

#5
post #3

That is a iPhone X like device, which only has Face ID or a PIN. A PIN is more secure than a fingerprint and Face ID. But at least use a combination of either one with a PIN to make it more secure. Since the device was already on and it directly showed the PIN screen, Face ID is disabled and instead he chooses to only use a very very weak PIN. Oh dear.

I'd be curious if Apple had anonymous telemetry that showed what people were picking for their phone unlock PINs. Everyone I've ever seen set one does this same type of thing, either all one number, or they draw a line through the middle. The more advanced maybe use a date like their birthday that they can actually remember.

It's just security theater.

Re: Congressman's phone password is 111111

#8
post #2

Aaaaaaand that's why these things aren't allowed in the SCIFs.

In a normal company, if an employee have bad practice for data protection and cyber security he might get fired

But what happen when it's a congressman?

We start to see now more and more data breaches that happens due to lack of basic knowledge in this subject....

Just 3 days ago was reveal that Equifax used 'admin' as username and password for sensitive data. ( https://finance.yahoo.com/news/equifax-password-username-adm...? )

In this case I'm sure that the IT person who's in charge for the system just give zero value to data protection and cyber security....

>According to an industry report by Shred-it, 47% of business leaders cited human error as the main cause of a data breach at their organization

https://www.perimeter81.com/blog/network/how-employees-open-...

Leave beside the fact that someone in this position should have better understanding of cyber security

I wonder if they get any kind of training from the government.

Re: Congressman's phone password is 111111

#10
I tell this story a lot. But I think in the time of smartphones and such it also represents the only real secure site I thought was truly secure from what I knew of it. This was before smartphones were common, but I think it was ahead of its time in that way.

I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they had "that site" that a few folks visited. Here was how that worked:

Nothing except your body and your clothes left the site, anything you brought stayed onsite (laptops that we brought onsite were left behind / effectively disposable, later you couldn't even bring those, they provided one). All that stuff belonged to the military / whomever you interacted with at the site.

No electronics, cameras, etc that were not previously improved were allowed and you were told you would not be leaving anytime soon if you had something "unexpected or unauthorized".

It was highly suggested that nothing was in your rental car other than your keys, the equipment you needed as they searched the car and the folks would take what they wished.

If you realized you had something you didn't want to in the car it was highly suggested you do not turn around if you are at all close to the location and to drive up and immediately tell them you dorked up and brought something. This was a fairly remote location so the probabbly knew you were coming before you saw the gate and the guards didn't like surprises.

Upon arrival you parked, were blindfolded and driven from the gate to the site, you never actually saw the outside of the site until you were in the building. You were never alone at anytime. Trips to the bathroom while at the site were monitored... in person by a guard with a rifle.

Now all that sounds ominous but everyone reported that the folks there were very professional (not friendly but professional).

The point of that whole story was that even a while ago someone said "any electronics" were a threat and decided that they had to go to extremes to limit their access. Still today I think that was the closest to a "sure" policy.

Post reply on HN