Live data from Hacker News

Congressman's phone password is 111111

gfycat.com

141–150 of 206 posts

Re: Congressman's phone password is 111111

#141

Earlier quoted context omitted.

[flagged]

Truly awful take. Enough with the "both sides" nonsense. One side is objectively bad. Even accidentally taking electronics into a SCIF can be grounds for losing ones security clearance and getting in major trouble. These people planned it, and executed that plan, for a publicity stunt. Enough has been said about why it wasn't necessary in any way for them to act like this, so I won't go into it, see other responses t…

I feel like HN is becoming more explicitly political and I think that this is a poor direction for the site to move.

Re: Congressman's phone password is 111111

#142

I always thought that Android's 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.

Well, if you had a flir camera looking over your shoulder the tracing effect (caused by localised heating of the screen) would still be there. I actually heard it is a legit method to defeat pin entry systems. If you can get to the terminal soon enough it was used, relevant keys will be a little hotter than the other. This will be visible with flir. Then all you have to do is figure out the order of digits.

If you have any camera (FLIR or otherwise) "looking over your shoulder" the method of secret entry is irrelevant.

Re: Congressman's phone password is 111111

#143

Earlier quoted context omitted.

[flagged]

Truly awful take. Enough with the "both sides" nonsense. One side is objectively bad. Even accidentally taking electronics into a SCIF can be grounds for losing ones security clearance and getting in major trouble. These people planned it, and executed that plan, for a publicity stunt. Enough has been said about why it wasn't necessary in any way for them to act like this, so I won't go into it, see other responses t…

Please don't take HN threads further into partisan flamewar. Nothing good can come of this here, if you define 'good' as what's expressed by the site guidelines.

https://news.ycombinator.com/newsguidelines.html

Re: Congressman's phone password is 111111

#144
post #10

I tell this story a lot. But I think in the time of smartphones and such it also represents the only real secure site I thought was truly secure from what I knew of it. This was before smartphones were common, but I think it was ahead of its time in that way. I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they…

If you knew the location of "the site" (because you drove to it) - what benefit was the blindfold for the site?

If "the site" was a building on a military base you'll still have no idea where the exact location is.

Re: Congressman's phone password is 111111

#145
post #27
post #10

I tell this story a lot. But I think in the time of smartphones and such it also represents the only real secure site I thought was truly secure from what I knew of it. This was before smartphones were common, but I think it was ahead of its time in that way. I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they…

Where was this? What was the "site?" What country? And what kind of work were they outsourcing to outside the military?

I'm not the original commenter but I'm familiar with policies like this. I grew up in Lynchburg, VA, where the Naval Nuclear Fuel facility is, operated by what was B&W. It had identical policies: everything that goes in, stays in, no one allowed in without clearance, no paper or electronics leave, air gapped computer network, etc. Not the monitored bathroom breaks, though....

Re: Congressman's phone password is 111111

#146
post #123
post #10

I tell this story a lot. But I think in the time of smartphones and such it also represents the only real secure site I thought was truly secure from what I knew of it. This was before smartphones were common, but I think it was ahead of its time in that way. I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they…

Why would you be willing to work in such conditions? If my employer demanded to send me to such a facility I would happily tell them to shove it and look for another job.

It wasn't a daily thing. It was a rare event for anyone to make that trip.

Most of the time we worked with traditional commercial customers that while some were secure, were nothing like I described.

Nobody seemed to have any concern with the policies / security.

Re: Congressman's phone password is 111111

#147
post #80
post #55

Earlier quoted context omitted.

A valid pattern on Android is to swipe the middle 3 dots backwards and forwards 3 times like left-middle-right-middle-left-middle-right. The smudge on the screen just shows it uses the middle three dots some number of times.

Not on Android 9 (tested on my Nokia 7 Plus). Once you pass on a dot, you can't get back to it. You also can't "jump over" dots (top left - top right is actually top left - top - top right).

They changed that at some point. Back in the KitKat days, I once pranked a friend by changing their pattern to the same pattern as before, but by skipping the middle dot (top left -> bottom right). If you did it fast enough, the gesture looked identical to the old pattern.

Re: Congressman's phone password is 111111

#148

I always thought that Android's 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.

You can often see these very obvious smudges on the screen

This, 1000x this! The whole "draw your code" is equal to 111111 codes, because both operations are easily possible to hack if you leave your phone to your peer or random freak. Isn't it the same issue as in many house alarm systems that you just need some UV light to note the most used keys to guess the code?

Re: Congressman's phone password is 111111

#149
post #90

I always thought that Android's 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.

Somehow I doubt this in practice still though.. my wife turned hers on, and it's the most obvious pattern you would think of. And honestly I set it to the same, just because it's the most convenient to use. If I make a convoluted pattern I won't be able to do it as easily. So still same old crap.. we tend to go to thinks we can remember and easily do- and that is not the most secure.

> it's the most obvious pattern you would think of.

First initial probably.

> honestly I set it to the same

Hmm. If it's the same, last name then? Maybe a diamond or something. I heard (Mitnick's book about best practices called The Art of Invisibility, chapter 1) many people don't use the corner dots very often, or they use an initial of their name.

I unintentionally can see people's phone patterns when they do it in view. At least with a passcode you can usually try to ignore it, or you have to try to pay attention. Those pattern ones show it visually in a way that's hard to ignore.

Re: Congressman's phone password is 111111

#150

If I were giving a security recommendation to famous people and congresspeople I would recommend using a password like this. You might think it’s incredibly insecure, but imagine this GIF contained that 6 digit number that the congressman uses for all of his accounts. Suddenly, a ton of other services and passwords are vulnerable to an attacker. In reality a lot of iPhones now require authentication at the app level…

[deleted]
Post reply on HN