Live data from Hacker News

Congressman's phone password is 111111

gfycat.com

191–200 of 206 posts

Re: Congressman's phone password is 111111

#191

The problem isn't the password or the camera that captured it. The problem is that the phone required a password in that scenario-- same user, phone never left his vicinity, probably not a long interval between uses. Being more selective about when to require a master password is a better protection model IMHO.

Soli on the new Pixel 4 could easily allow that.

Or fingerprint readers, which most phones have had for years. It's possible that the DoD standards for the phone he has requires that biometrics be disabled.

Re: Congressman's phone password is 111111

#192

I worked for a well known company today, many years ago when it was smaller. When the IT team created new accounts for employees, it was the standard Pa$$word password for everyone. It was up to the user to change their password. They had no password rotating rules or requirements. Anyway, many years later after I started, IT hires a person who wants to do good while in IT. This person discovers the CEO is still usin…

> IT person skipping over the chain of command was bad enough it got them fired.

Isn't this roughly the opposite of what you want in an org? Otherwise there can be the failure mode of only good news getting reported up, so the folks running the company base their decisions on finely cultivated bullshit and are completely isolated from reality.

Re: Congressman's phone password is 111111

#193
post #81

Earlier quoted context omitted.

The boindfolds seem like extra work, I would just get a SUV and totally black out the rear, or well, put in some seats in the rear of a delivery van. But I guess the boindfolds also had a psychological effect of "we mean business".

A blindfold allows someone to be in close proximity to the person while also retain g visibility and communication with that person and other people (e.g. the driver). If you lack out a special cabi area for a vehicle, either you are leaving them to their own devices in that area, or limiting the senses of your own staff you put in to watch them. Finally, it's just a lot more expensive and cumbersome to have a large…

> If you lack out a special cabi area

"if you black out a special cab area". :/

Is it just me, or does it feel like the SwiftKey keyboard for android has gotten much worse in its autocorrect in the last couple years?

Re: Congressman's phone password is 111111

#194
post #100

Earlier quoted context omitted.

You can also most probably install an application that will be able to catch both your pins and subsequently, much more data. Considering that both your password and email are protected by pins, why not have a pin on the device too?

Looking at email or passwords is rare. Reading some quick news, opening maps, listening to music and so forth - I don't want to use a pin to access all of those things. Someone installing an app to catch pins that I typed in and then giving me back my phone...then waiting until I typed a pin and stealing my phone again seems like a bit of a hassle. Out of curiosity though - what app in the app store allows you to do…

> .then waiting until I typed a pin and stealing my phone again seems like a bit of a hassle.

Why would you have to steal it again?

> Or, do they have to jail break my phone to do it?

They will most likely have to jailbreak it.

> I just don't worry about things and shit seems to work out.

Yeah, sure, nobody ever said it happens often, it's for the time it happens that it save you so much trouble.

A friend got his credit card stolen recently, no big deal, I'm in Canada and the bank take all the blame in theses cases. It still was way too much trouble to get a new card because the guy changed his card information and the bank couldn't validate his identity.

It's not always about what you may lose, it's about what may happens to get back from it.

> It's just stuff. Perhaps if someone stole everything from me, I'd be even more free than I am now.

I don't believe you, but good for you if believe it yourself.

Re: Congressman's phone password is 111111

#195
post #184
post #174

Earlier quoted context omitted.

Just trying to be a better HN citizen, so is there something specific I did wrong here that crossed a line or is it just a "know it when I see it" situation? I didn't reference anything partisan and was simply relating a recent political event to both the general topic of poor congressional cybersecurity and the specific topic that duxup was talking about regarding securing a site from electronic devices. It was the…

I hear you and appreciate your wish to be a good community member! The value of an HN comment is the expected value of its future subthread—i.e. itself, plus the sum of the probability distribution of the responses it may receive. In this case the EV of your post was negative: first because it brought in a partisan stunt that was still hot from the news of the moment; second by framing it one-sidedly ("barged into...…

Thanks, I appreciate the thorough explanation. I agree that the "expected value" idea is an interesting one and I see how when viewed through that prism that the language I used and that linked source used can be seen as biased and more likely to incite a more partisan response.

Although I am still not sure I agree with the general guideline of not bringing up something like that incident as I believe it was on topic to both the post and the comment I replied to. My comment might have been the one to inspire a flamewar type response, but it wasn't the only comment that mentioned that incident in general. That said, I will try to be more mindful of that in the future.

Re: Congressman's phone password is 111111

#196
post #11

111111 is perfectly acceptable for a phone password. His password was just broadcast to the entire world; at least using 111111 means that he doesn't have any illusions about how secure it is. Phone passwords are for protecting things from your family.

>Phone passwords are for protecting things from your family. I think what you actually mean is anyone who has physical access to your phone. If you lose your phone or it is taken by authorities, then you are at risk of having strangers access your data.

Strangers already have access to all my data; I use Gmail [0] for most of my important personal emailing, metadata like website browsing habits is already snoop-able. iMessages might be secure, but there isn't anything substantial there that can't be dug up elsewhere.

If this guy was relying on any password to protect his phone from physical access then he is in for a nasty shock - whatever his password was, his adversaries would know it after this video. That fact that it was 111111 doesn't actually change anything.

He's in the US government. If he is up to something and he has enemies; it will get leaked. If he doesn't have enemies the lack of security isn't so terrible. His work is supposed to all be in the public eye anyway.

[0] https://nakedsecurity.sophos.com/2018/09/06/ungagged-google-...

Re: Congressman's phone password is 111111

#197
post #11

111111 is perfectly acceptable for a phone password. His password was just broadcast to the entire world; at least using 111111 means that he doesn't have any illusions about how secure it is. Phone passwords are for protecting things from your family.

>Phone passwords are for protecting things from your family. That's a bit of a sad, unusual sentiment

Well I can expend that to friends as well if you like. Who do you think your password is protecting you from? Are you frequently at odds with law enforcement?

Most people aren't; it isn't a feature to protect people from governments (I wish we had more features that did). Encryption is a good thing in a general sense but for most users they are more likely to lock themselves out of their own data than protect themselves from anything outside their close friends and family.

Re: Congressman's phone password is 111111

#198
post #27

Earlier quoted context omitted.

Where was this? What was the "site?" What country? And what kind of work were they outsourcing to outside the military?

Given the intensity of the security described, I strongly suspect the answer to each of those questions is "I can't say". We outsource pretty much anything to contractors, though.

...including security clearance investigations...

Re: Congressman's phone password is 111111

#199
post #41

I don't lock my phone at all. Never have. However, with the new iPhones that don't have a home button, I believe that Apple is forcing you to either use face unlock or a passcode. There is no choice to just leave it unlocked. So, as soon as my iPhone 6s stops working, I will have to choose to: 1) Give in and use my face to unlock. 2) Use a dumb passcode like 000000. 3) Upgrade to the newest iPhone that still has a ho…

I think your point may be that he doesn't have anything private on the phone to worry about or anything that needs to be kept secure? I think the argument hidden in the headline here is that since this is a device owned by a congressman, and allowed inside this particular meeting, it has information on it that may be confidential, and therefore needs a much stronger password. My phone has access to my email, phone nu…

On the flip side, one could also argue that as a public employee, everything that congressman does should be on the public record out in the light for everyone to see, and that the best security would actually be zero security.

This would also have the positive side effect of making it really hard for public employees to engage in corrupt and illicit behavior (which, as we all know, is so rampant that it's practically industry standard at this point).

Re: Congressman's phone password is 111111

#200

Earlier quoted context omitted.

Sure, but if your angle of attack is "someone swiped my phone off my desk and wants to unlock it within the next 30 minutes before I wipe it remotely" then 111111 is as good as literally any other 6-digit pin code, unless the attacker just tries 111111. In which case 999999 is probably a better choice.

> Sure, but if your angle of attack is "someone swiped my phone off my desk and wants to unlock it within the next 30 minutes before I wipe it remotely" then 111111 is as good as literally any other 6-digit pin code, unless the attacker just tries 111111. In which case 999999 is probably a better choice. Asking "How secure is this?" is essentially the same as "What angles of attack would this prevent?" So if your pho…

I was talking about odds of the iphone combination in general.

If you really want to delve into the specific scenario of a US Congressman then there are many more factors like how are you going to get access to the phone at all? How are you going to avoid the lost mode activating? Iphones have limited tries before permanently disabling so how many are you going to risk with a dictionary attempt? Would you really put 111111 as the first try considering most people wouldn't use that?

Post reply on HN