Live data from Hacker News

PAM Duress – Alternate passwords for panic situations

github.com

261–270 of 358 posts

Re: PAM Duress – Alternate passwords for panic situations

#261
post #228

Earlier quoted context omitted.

Tell them you feel uneasy giving out details over the phone to an inbound caller, hang up and call their service line directly. The only way you can be sure you are talking to your bank is if you are calling them.

Can you really be sure though? How hard is it really to redirect outgoing calls?

You'd have to have access to the cell tower your phone is connected to. At that point the attack is pretty sophisticated and very targeted.

Re: PAM Duress – Alternate passwords for panic situations

#262

I hate when my bank calls me about something and then asks to confirm my identity prior to giving out details about my account. Even when I think I know what it is about (e.g., a transaction with my card was declined just before the phone call), I feel very strange giving out any information to an inbound caller. One thing I have thought about doing is providing mistaken information to the caller and see if they go a…

>Does anyone else have any ideas for how to authenticate a BigCorp caller whose corporate policies do not allow them to provide any account information to the people they are calling?

Definitely. Hang up the phone and call the phone number on the card associated with your account or look up the appropriate telephone number and call them back.

If they're legit, they will be perfectly fine with that. If not, they'll likely squawk about it.

Either way, the correct process begins with you hanging up without providing any information to the caller.

My bank will also send SMS "fraud alerts" with a request to confirm or deny a transaction. That's the same situation, IMHO and the right action is to call the known to be valid phone number for their customer service.

Perhaps there are other, fancier ways to do something like this, but as a general rule, scammers can't change the customer service phone number printed on your card, or hack third party services just to give you a fake phone number online.

Re: PAM Duress – Alternate passwords for panic situations

#263

Earlier quoted context omitted.

That makes sense. Sorting things out takes time. But trying to create an illusion that no alarm was triggered to prevent criminals from gaining knowledge: not a reason to imprison an innocent person.

>imprison an innocent person. Kind a hard word to use for an arrest. In many places police can arrest you for some period if they suspect you have committed a crime. This is no different. No need for sensational language.

In the US they can’t do anything unless they have “probable cause” you committed a crime. That’s broad, but it excludes “this guy pushed the number 6 three times in a row.”

And “imprison” and “arrest” are pretty darn close. In the US, when you are arrested, you are usually searched, fingerprinted, and a mugshot is taken.

The mugshot can become a public record. There are websites that match mugshots to names, and make money by being paid to take mugshots down.

Nobody wants the google result for their name to be a mugshot.

Re: PAM Duress – Alternate passwords for panic situations

#264
post #216

Earlier quoted context omitted.

I'd always assumed (UK) that 9 was a deliberate choice to make it easier to dial the emergency number, 999, because you can just mash 9 until something happens. I guess if it's the same number in all other countries who have a range of emergency numbers, then that might not be the reason.

My working theory is that in old times phones had rotary dial instead of key pad. Number 1 was the longest to dial, 9 was the shortest (as I remember from childhood days). Thus, fastest way to dial 3 digit code was to use numbers with as much as 9 as possible (997,998,999).

On rotaryphones 0 takes the longest to dial, then comes the 9. 1 was the fastest to dial, I think this is the reason why emergency numbers tend to have the lower numbers.

https://en.wikipedia.org/wiki/Rotary_dial

Re: PAM Duress – Alternate passwords for panic situations

#265

I hate when my bank calls me about something and then asks to confirm my identity prior to giving out details about my account. Even when I think I know what it is about (e.g., a transaction with my card was declined just before the phone call), I feel very strange giving out any information to an inbound caller. One thing I have thought about doing is providing mistaken information to the caller and see if they go a…

Most banks here (UK) have a mobile app, so I've always wondered why they don't use that to auth the call?

    Bank: Hey I'm calling from HSBC, want to verify it?
    Me: Sure
    Bank: Ok, so open you mobile app, and enter 637482
    Me: Ok, cool thats given me 274893
    Bank: Yep, that's all confirmed so ...

Re: PAM Duress – Alternate passwords for panic situations

#266

Earlier quoted context omitted.

Tell them you feel uneasy giving out details over the phone to an inbound caller, hang up and call their service line directly. The only way you can be sure you are talking to your bank is if you are calling them.

Wait a couple of minutes or call back from a different phone. In the UK it may still be possible for an attacker to hold the line open after you hang up - and then simulate the dial tone.

I've heard this, but I don't understand it. Doesn't the UI feel completely different when it comes to placing a call versus using the keypad on an existing call? On android at least you have to explicitly show the keypad.

Re: PAM Duress – Alternate passwords for panic situations

#267

Earlier quoted context omitted.

I grew up with a rotary phone. From memory, 1 was the shortest to dial, 9 the longest.

Actually this is country specific AFAIK. Wikipedia has a picture[1] of a phone from New Zealand which has 9 as the shortest. [1]: https://en.wikipedia.org/wiki/Rotary_dial#/media/File:New_Ze...

This might also explain why the Kiwi emergency number is 111 as a counterpoint to the UK's 999. Interesting!

Re: PAM Duress – Alternate passwords for panic situations

#268
post #174
post #146

Earlier quoted context omitted.

Time to post this again: https://www.youtube.com/watch?v=d-7o9xYp7eE (Don't talk to the police)

Everytime this is posted I feel the need to mention to Brits specifically: this does not apply. "It may harm your defence if when questioned you fail to mention something you will later rely on in court". Failure to answer can seriously harm your defence and I've heard of people I personally know (though I wasn't in the courtroom) where the prosecution hammered the point that they "came up with a plausible sounding s…

While you do not have a right to avoid self incrimination in the UK, you do have a right to have a lawyer present when you are being questioned.

Re: PAM Duress – Alternate passwords for panic situations

#269
Do not carry devices with sensitive data around if not necessary, simple as. All this hidden user stuff will go nowhere. Have the data encrypted on a server and access it remotely.

Anything else is simply not safe at all or might cost you prison time, check the UK laws on this.

Post reply on HN