Live data from Hacker News

Plenty of Fish Hacked

plentyoffish.wordpress.com

41–50 of 104 posts

Re: Plenty of Fish Hacked

#41
post #9

Earlier quoted context omitted.

If there is an option to use some kind of hardware token with your banking then I would strongly advise you to take that. Having just a password to protect your bank account sounds pretty scary to me. That's about as juicy as it gets. I'm paranoid enough about my servers having 'just' a password to protect them (oh, and an ACL), if my bank accounts would have only a password I wouldn't sleep. Every time I log on I ha…

In Denmark the currently-being-phased-in solution is a low-tech version of two-factor authentication. Instead of a hardware dongle, the centrally-administered "NemID" system issues you with a physical code card with some numerical codes on it. You enter your NemID password, your CPR number (Denmark's citizen-ID number), and the next unused code on the card. When there's fewer than 20 unused codes, the system notices…

This resembles the most common way of authentication for online banking in Germany (a PIN and a list of transaction codes, so-called TANs).

Do you always have to pick the next one-time code in the printed sequence? In Germany, you used to be free to pick any of the unused TANs, which made phishing really simple. Nowadays it's more common for a bank to challenge you to a randomly chosen TAN.

Re: Plenty of Fish Hacked

#42
post #27

Earlier quoted context omitted.

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

> Our debit and credit cards are being replaced with cards with chips embedded Do you want to know something scary about that. We've had Chip and PIN as the de-facto standard in the UK for some years now (although I do remember it coming in). The really scary thing is; my parents remember it being widely used in Germany in the late 80's. Has it really taken that long to get to Canada?

Chip and Pin in the late 80s in Germany?

It is true that paying in stores with my German ATM card and its PIN was nothing new when I got my first bank account in the mid-90s. However, that system used the magnetic stripe of the card (which is why skimming is still so attractive here); smart-card chips on bank cards were introduced a lot more recently.

Re: Plenty of Fish Hacked

#43
post #42
post #27

Earlier quoted context omitted.

> Our debit and credit cards are being replaced with cards with chips embedded Do you want to know something scary about that. We've had Chip and PIN as the de-facto standard in the UK for some years now (although I do remember it coming in). The really scary thing is; my parents remember it being widely used in Germany in the late 80's. Has it really taken that long to get to Canada?

Chip and Pin in the late 80s in Germany? It is true that paying in stores with my German ATM card and its PIN was nothing new when I got my first bank account in the mid-90s. However, that system used the magnetic stripe of the card (which is why skimming is still so attractive here); smart-card chips on bank cards were introduced a lot more recently.

I only have my parents recollections about this (we lived in Germany in the late 80's, but I was 0 & so can't recall ;)) - possibly it was swipe & pin, I'd have to ask.

But when the Chip 'n Pin system came in here in the UK my Dad's first comment was "oh, they were using that in Germany in '87/88"

Re: Plenty of Fish Hacked

#45

Earlier quoted context omitted.

The upside is that the NemID system gets the average citizen to a point where his/her family (and close friends) are the largest security problem. It is much more difficult for hackers in Argentina and Russia to get into your bank account when they need access to a piece of paper. If is impossible to protect against your own family: the have hardware access to your computer, they can intercept all your paper mail, th…

If there is one thing I would like it would be the option to specifically authorize a set of IP addresses allowed to access my bank account rather than the implicit way it is done right now.

I totally agree with this. I even had the SSH firewall rule of my Mumble voice server for my WoW guild set to only allow my home connection. One downside is if I'm ever given a different IP address by my ISP, I'd have to go to work and change it. Minor inconvenience but this isn't a crucial service.

Re: Plenty of Fish Hacked

#46
post #8

This is extortion, plain and simple.

From Markus' account, it sure looks like that; but note that a "chris russo" says, in the comments, that he's only given a proof of concept and that the web server logs will show that he didn't make a full dump.

Of course, sending a PoC with an offer to fix the security does have a "nice website you have there, it'd be a shame if something happened to it" vibe to it; still, it's factually different from trying to extort money from a company by dangling a dump of their customer database.

Re: Plenty of Fish Hacked

#47

Earlier quoted context omitted.

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

The weird thing is that Blizzard will cheerfully sell you a $7 hardware token to protect your imaginary WoW gold and equipment, but I don't know of any US banks that offer one to protect your actual money.

SOP for Citibusiness accounts.

Re: Plenty of Fish Hacked

#49

Earlier quoted context omitted.

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

> Are you European? Yes, working from NL at the moment. > Unfortunately, such a thing seems all but unheard of here in Canada. That sucks! > Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. Ok. > I have noticed that when I login from a new computer (for example, w…

>> Are you European?

>Yes, working from NL at the moment.

Same here.

With one bank I must use the hardware token solution (and I am able to use any device, not just the one issued to me). With another bank I must register my mobile telephone number with them and they send me a text with an authorisation token whenever I need one.

I much prefer the hardware solution even though it is a major inconvenience when travelling light.

Re: Plenty of Fish Hacked

#50
post #38

Just got in contact with Chris Russo who hacked PlentyOfFish His version of the events here -> http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp...

While we were creating the legal documents in order to proceed, Markus Frind got progressively more aggressive and unresposive with us, and told us to speak with their employees, Kate and Jay, because there was a serial killer, murdering people from the website.

If you ask me, both of them sound crazy and deluded. Marcus' story doesn't make much sense if you read the email on that site[1], but carrying on about serial killers doesn't help your case much either. And that freelancer link is just a red herring - I can't see what it's got to do with the case at hand.

[1] Update: Or even if you read his own post: "I listened in the background and I closed the breach if indeed there was one while my wife was on the phone". Er, was there a breach or not? And why are you calling his mother and not the police?

Post reply on HN