Live data from Hacker News

Congressman's phone password is 111111

gfycat.com

61–70 of 206 posts

Re: Congressman's phone password is 111111

#62
post #15
post #9

Earlier quoted context omitted.

Why would age determine your intelligence?

Nothing to do with intelligence either. Most people don't grasp the consequences of bad OPSEC, though they can fairly well understand why they should lock their door when away from home. Those people lack education on the topic.

It was a funny conversation with a senior developer when I noticed he had his business card and his key card to work on the same extensible thingy that you clip on to your pants.

I remarked there's a reason why the key cards are unmarked, right?

It isn't just individuals who can't into OPSEC though. Soon after this conversation, the company created a policy saying you have to pay $10 to get a new key card if you lose your key card.

I thought that was stupid. Now, suddenly you have incentivized people to NOT report they don't have possession of their key card any more. We want people to report the instant they lose access to their key card, not three days later when they have exhausted all options. My understanding is that you can easily reactivate a key card if it is found again and the risk of unreported lost cards outweighs the cost of a new key card.

Re: Congressman's phone password is 111111

#66

I always thought that Android's 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.

Is there a reason why the numbers aren't scrambled? This way you at least wouldn't be able to tell the password unless you saw the actual numbers.

Re: Congressman's phone password is 111111

#67

Isn’t the real problem here that this was caught on video? Otherwise it’s just as secure as any other code.

No, it is not. These sorts of "I'm annoyed that I'm being forced to put in a password so I'll put the easiest one to type" passwords are in even the most basic password dictionaries, and are therefore susceptible to dictionary attack.

Re: Congressman's phone password is 111111

#68

Yup, not sure why we expect good security practices out of a group who's average age is 60

In my 20+ years in IT I haven't found much correlation between age and security practices, personally.

I have worked with a few alpha types who considered themselves too important to waste time memorizing a password. I'm not sure if it's the case here, but I'd guess that brand of entitlement has a higher incidence rate within the halls of congress.

Re: Congressman's phone password is 111111

#69

I always thought that Android's 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.

Is there a reason why the numbers aren't scrambled? This way you at least wouldn't be able to tell the password unless you saw the actual numbers.

I can't imagine a more annoying feature. My bank already does this where I cannot use the keyboard to type in digits, I have to use their own on-screen keyboard that's scrambled between every digit(!!!) and I can't imagine anything like that anywhere near my phone. Either pin-based protection is good enough for you, or if you need more security then switch to full a-Z password.
Post reply on HN