Live data from Hacker News

Plenty of Fish Hacked

plentyoffish.wordpress.com

21–30 of 104 posts

Re: Plenty of Fish Hacked

#21

Earlier quoted context omitted.

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

> Are you European? Yes, working from NL at the moment. > Unfortunately, such a thing seems all but unheard of here in Canada. That sucks! > Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. Ok. > I have noticed that when I login from a new computer (for example, w…

Are you liable for fraud committed with your account online?

Or would the bank indemnify you if your password were used to clean out your accounts?

Honestly, I have no idea. I really should look into the fine print in the online TOS/Rules&Regs.

Re: Plenty of Fish Hacked

#22
post #9

Earlier quoted context omitted.

If there is an option to use some kind of hardware token with your banking then I would strongly advise you to take that. Having just a password to protect your bank account sounds pretty scary to me. That's about as juicy as it gets. I'm paranoid enough about my servers having 'just' a password to protect them (oh, and an ACL), if my bank accounts would have only a password I wouldn't sleep. Every time I log on I ha…

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

The weird thing is that Blizzard will cheerfully sell you a $7 hardware token to protect your imaginary WoW gold and equipment, but I don't know of any US banks that offer one to protect your actual money.

Re: Plenty of Fish Hacked

#23
post #18
post #13

Earlier quoted context omitted.

Grumo media looks pretty cool. Maybe you shouldn't regret it? I'm doing a startup in Vancouver as well. Your videos look awesome but are out of my current budget. :(

I just checked your profile, do you also do iPhone apps? We're a cool startup in Vancouver and we're looking for help with our iPhone development, maybe we can chat

Yup, definitely do do that. I'll email you right now. team at summify.com?

Re: Plenty of Fish Hacked

#24
post #9

Earlier quoted context omitted.

It's actually worse than that. I don't know what it's like now, since I haven't used POF since 2008 or so when I met my current girlfriend (though I only remembered to kill the account a few months back), but back then they would actually send you reminders every so often - I want to say once a week - that included your plain text password as a reminder. I think this is just the kick in the ass I needed to go through…

If there is an option to use some kind of hardware token with your banking then I would strongly advise you to take that. Having just a password to protect your bank account sounds pretty scary to me. That's about as juicy as it gets. I'm paranoid enough about my servers having 'just' a password to protect them (oh, and an ACL), if my bank accounts would have only a password I wouldn't sleep. Every time I log on I ha…

In Denmark the currently-being-phased-in solution is a low-tech version of two-factor authentication. Instead of a hardware dongle, the centrally-administered "NemID" system issues you with a physical code card with some numerical codes on it. You enter your NemID password, your CPR number (Denmark's citizen-ID number), and the next unused code on the card. When there's fewer than 20 unused codes, the system notices and mails you a new card.

The downside is that there's now a single point of failure, albeit with more factors. If you get someone's CPR number, their NemID password, and their current NemID card with some indication on it of which the next unused code is (most people mark off the used codes), you can log into everything: all Danish banks, the tax authority, the municipal authorities, your library account, etc., etc.

They do try to minimize it by writing strongly worded warnings everywhere not to store your NemID password in your wallet. A typical wallet contains a Danish health card with CPR number, and the NemID code card, so it's fairly important that the NemID password not also be there.

Re: Plenty of Fish Hacked

#26
post #9

Earlier quoted context omitted.

If there is an option to use some kind of hardware token with your banking then I would strongly advise you to take that. Having just a password to protect your bank account sounds pretty scary to me. That's about as juicy as it gets. I'm paranoid enough about my servers having 'just' a password to protect them (oh, and an ACL), if my bank accounts would have only a password I wouldn't sleep. Every time I log on I ha…

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

The chips are most likely for EMV[1], which essentially puts some intelligence on the card in the form of an IC chip, and allows the card to make approve/deny decisions based on rules of the issuing bank. With EMV cards, the transaction is more like a negotiation, and the card may reject at any point.

Of course, like anything, there will be vulnerabilities, and in the interests of usability, some issuing banks will relax restrictions.

Because of the crypto involved in the back and forth communication between hardware and card, EMV transactions piss off a lot of customers, it can easily take 2-3 times more time to process a transaction when compared to a mag-swipe.

Though it does reduce the chance of your card getting skimmed. (Skimming is where your details are captured during the swipe. Yes, a swipe through the appropriate device reveals all the information required to completely duplicate the card.)

[1] http://en.wikipedia.org/wiki/EMV

Re: Plenty of Fish Hacked

#27
post #9

Earlier quoted context omitted.

If there is an option to use some kind of hardware token with your banking then I would strongly advise you to take that. Having just a password to protect your bank account sounds pretty scary to me. That's about as juicy as it gets. I'm paranoid enough about my servers having 'just' a password to protect them (oh, and an ACL), if my bank accounts would have only a password I wouldn't sleep. Every time I log on I ha…

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

> Our debit and credit cards are being replaced with cards with chips embedded

Do you want to know something scary about that. We've had Chip and PIN as the de-facto standard in the UK for some years now (although I do remember it coming in).

The really scary thing is; my parents remember it being widely used in Germany in the late 80's.

Has it really taken that long to get to Canada?

Re: Plenty of Fish Hacked

#28

Earlier quoted context omitted.

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

> Are you European? Yes, working from NL at the moment. > Unfortunately, such a thing seems all but unheard of here in Canada. That sucks! > Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. Ok. > I have noticed that when I login from a new computer (for example, w…

>Are you liable for fraud committed with your account online?

Not with TD Canada Trust, to an extent:

"As set out in our account agreements, you are responsible for maintaining the care, control and confidentiality of your Access Card number, Connect ID, and passwords. TD Bank Financial Group is not responsible for unauthorized access to accounts online or losses that occur as a result of you voluntarily disclosing your Access Card number, Connect ID, or passwords, or the careless or improper handling, storing or disclosure by you of this information. In the event of loss, theft, misuse or compromise of your Access Card, Connect ID, and/or passwords, you must notify TD Bank Financial Group immediately."[1]

The "Known IP" is a bit more complicated. I was travelling through South America recently, and could always access it from my phone. However, accessing from a hostel or internet cafe required answering a security question.

http://www.td.com/privacyandsecurity/guarantee.jsp

Re: Plenty of Fish Hacked

#29

Earlier quoted context omitted.

> Are you European? Yes, working from NL at the moment. > Unfortunately, such a thing seems all but unheard of here in Canada. That sucks! > Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. Ok. > I have noticed that when I login from a new computer (for example, w…

Are you liable for fraud committed with your account online? Or would the bank indemnify you if your password were used to clean out your accounts? Honestly, I have no idea. I really should look into the fine print in the online TOS/Rules&Regs.

The system we use here has it's own vulnerabilities (after all, if your card is stolen and the pin is known then any token can be used to authorize transactions, and there are known ways to attack the card electronically) but it makes it at least a little bit harder.

On top of that we do have indemnification.

Combating electronic banking fraud is an ever lasting game of leap frog, it looks like the banks are at least one step too far behind. At least they have the extra challenge question, I hope you made them hard enough :)

Re: Plenty of Fish Hacked

#30
post #15

Related, but slightly off-topic. When I read this post on my iPhone, I saw a match.com ad on the top of the page. match.com competes with Plenty Of Fish. POF is a multi-million dollar business. I'm surprised that they aren't paying Wordpress to provide an ad-free experience.

POF is entirely funded by ads from paid-for dating sites. It's a weird business model, but it seems lucrative.
Post reply on HN