Live data from Hacker News

Congressman's phone password is 111111

gfycat.com

41–50 of 206 posts

Re: Congressman's phone password is 111111

#41

I don't lock my phone at all. Never have. However, with the new iPhones that don't have a home button, I believe that Apple is forcing you to either use face unlock or a passcode. There is no choice to just leave it unlocked. So, as soon as my iPhone 6s stops working, I will have to choose to: 1) Give in and use my face to unlock. 2) Use a dumb passcode like 000000. 3) Upgrade to the newest iPhone that still has a ho…

I think your point may be that he doesn't have anything private on the phone to worry about or anything that needs to be kept secure?

I think the argument hidden in the headline here is that since this is a device owned by a congressman, and allowed inside this particular meeting, it has information on it that may be confidential, and therefore needs a much stronger password.

My phone has access to my email, phone number, texting.

With these 3 things you can get into my bank account, access to my domains, and into any online account I hold.

Then, personally and professionally, I manage other peoples' accounts, so, with my phone, you can probably social-engineer your way into those as well.

My point is, if you are married, have a job, email, or have other people in your life that you don't want to go through an identity theft crisis, or get hacked, stalked, etc, you should lock your phone.

Maybe you aren't the target, but you are the wide-open back door into their life.

Re: Congressman's phone password is 111111

#42

The problem isn't the password or the camera that captured it. The problem is that the phone required a password in that scenario-- same user, phone never left his vicinity, probably not a long interval between uses. Being more selective about when to require a master password is a better protection model IMHO.

Non-complex passwords are routinely an issue. Unless he's staring at his phone, it's good practice to prompt for a password.

Re: Congressman's phone password is 111111

#43
I wonder what AI tech is being developed around detecting pin code entry on phones using passive CCTV networks.

If you process the feeds for public transit security cameras, I wouldn't be surprised if you can read the pin codes for a huge swath of the population. It would also reduce the need for law enforcement to try to get a suspect to tell them their passcode. Just look up that time they rode the subway 3 weeks ago and watch them enter it.

Re: Congressman's phone password is 111111

#44
post #3

That is a iPhone X like device, which only has Face ID or a PIN. A PIN is more secure than a fingerprint and Face ID. But at least use a combination of either one with a PIN to make it more secure. Since the device was already on and it directly showed the PIN screen, Face ID is disabled and instead he chooses to only use a very very weak PIN. Oh dear.

I'd be curious if Apple had anonymous telemetry that showed what people were picking for their phone unlock PINs. Everyone I've ever seen set one does this same type of thing, either all one number, or they draw a line through the middle. The more advanced maybe use a date like their birthday that they can actually remember. It's just security theater.

No, PINs are not transmitted to Apple.

"What this process appears to show is that Apple never sees, handles, or stores your device passcode or password in unencrypted form, and it never passes the passcode or password over anything but secure transport. It requires only your Apple ID account name and password, sent over HTTPS, as the first stage of logging into iCloud, but not for the later stages."

Excerpt from: https://tidbits.com/2019/09/26/why-apple-asks-for-your-passc...

Re: Congressman's phone password is 111111

#45
post #27
post #10

I tell this story a lot. But I think in the time of smartphones and such it also represents the only real secure site I thought was truly secure from what I knew of it. This was before smartphones were common, but I think it was ahead of its time in that way. I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they…

Where was this? What was the "site?" What country? And what kind of work were they outsourcing to outside the military?

I'm guessing Cavalier, Mountain Home, or Tonopah.

Re: Congressman's phone password is 111111

#46
post #34

I always thought that Android's 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.

More importantly, Android's pattern draw allows the user to pass on an already traced line. That way you can't guess the pattern just by looking at the screen smudges.

Sorry, I don't understand what you're trying to say. Why can't you guess the pattern by looking at the smudges?

Re: Congressman's phone password is 111111

#47

I don't lock my phone at all. Never have. However, with the new iPhones that don't have a home button, I believe that Apple is forcing you to either use face unlock or a passcode. There is no choice to just leave it unlocked. So, as soon as my iPhone 6s stops working, I will have to choose to: 1) Give in and use my face to unlock. 2) Use a dumb passcode like 000000. 3) Upgrade to the newest iPhone that still has a ho…

Why is it that you choose not to? I think it would be helpful to understand your use case and how you balance your personal tolerance for risk and consequences so we can better consider users like yourself.

(Not the OP.)

I have an older phone that is basically a home remote for various things. There is no reason for it to lock, it would be annoying.

Re: Congressman's phone password is 111111

#48

I don't lock my phone at all. Never have. However, with the new iPhones that don't have a home button, I believe that Apple is forcing you to either use face unlock or a passcode. There is no choice to just leave it unlocked. So, as soon as my iPhone 6s stops working, I will have to choose to: 1) Give in and use my face to unlock. 2) Use a dumb passcode like 000000. 3) Upgrade to the newest iPhone that still has a ho…

I was just using an iPhone without a home button and you don’t need a passcode or facial recognition to use it. Just swipe up from the bottom.

Re: Congressman's phone password is 111111

#49

I don't lock my phone at all. Never have. However, with the new iPhones that don't have a home button, I believe that Apple is forcing you to either use face unlock or a passcode. There is no choice to just leave it unlocked. So, as soon as my iPhone 6s stops working, I will have to choose to: 1) Give in and use my face to unlock. 2) Use a dumb passcode like 000000. 3) Upgrade to the newest iPhone that still has a ho…

How do all the people you communicate with via email, text, etc., feel about their contact information and messages with you being so easily accessible? Securing your devices isn't just about you...

Re: Congressman's phone password is 111111

#50
post #10

I tell this story a lot. But I think in the time of smartphones and such it also represents the only real secure site I thought was truly secure from what I knew of it. This was before smartphones were common, but I think it was ahead of its time in that way. I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they…

I'm hoping they've implemented some form of localized EMP that you have to pass through now to leave, because large storage is so incredibly small now that it would be impossible to discern it from articles of clothing.

The "hard" part is really just getting the data off the computer in the first place, which is probably why they don't allow bringing in technology anymore.

I wonder how much of a micro computer could be smuggled in one or two parts at a time, stored in articles of clothing, with the intent of simply saving data to a micro SD card which would be the only thing you need to smuggle back out. You would need to be able to assemble the device without soldering.

I guess the easiest would be to build a digital camera to record the screen or photos instead of trying to plug into the computers themselves which probably have robust host intrustion detection and prevention. Or perhaps if you could just record the digital output of the computer before it reaches the monitor. That could be prevented with some form of HDCP though, I think.

This all sounds kind of like a science fiction movie (or In the Line of Fire or that Snowden movie) but it's an interesting thought exercise in any case.

Post reply on HN