Live data from Hacker News

The New Ten-Factor Authentication Processes

mcsweeneys.net

91–100 of 107 posts

Re: The New Ten-Factor Authentication Processes

#91

Earlier quoted context omitted.

If someone scrapes your clipboard or records your screen for example, this still adds a second layer of protection.

They can't scrape the clipboard because of autofill, and they can't record the screen because passwords appear as ******.

> passwords appear as hunter2.

You should be careful about copy pasting your password on the internet.

Re: The New Ten-Factor Authentication Processes

#92

My favourite stupidity is related to self-service password reset questions. You know the type: "What's your favourite animal?", and other easily-guessed and easily obtained information hackers can use. I always put in some gibberish by mashing the keyboard and make sure to record them somewhere safe just in case I need a password reset. I memorise my password and that should be fine, right? Well, I was overseas with…

The most insane security question I've encountered is on united.com where they have you select your question _and answer_ from a dropdown.

and the questions are insanely specific

Re: The New Ten-Factor Authentication Processes

#93

My favourite stupidity is related to self-service password reset questions. You know the type: "What's your favourite animal?", and other easily-guessed and easily obtained information hackers can use. I always put in some gibberish by mashing the keyboard and make sure to record them somewhere safe just in case I need a password reset. I memorise my password and that should be fine, right? Well, I was overseas with…

I had to tell some support guy my gibberish over the phone to get them to talk to me at all ... what a fun.

Re: The New Ten-Factor Authentication Processes

#94

My favourite stupidity is related to self-service password reset questions. You know the type: "What's your favourite animal?", and other easily-guessed and easily obtained information hackers can use. I always put in some gibberish by mashing the keyboard and make sure to record them somewhere safe just in case I need a password reset. I memorise my password and that should be fine, right? Well, I was overseas with…

A travel agent had ridiculous and not explained rules for password composition so after many many tries I ended up very angry and with a password on the lines of "how about f* you idiots" (I use a password manager too). Later I wasn't able to login and the phone support told me it was because I used profanity in the password.

Re: The New Ten-Factor Authentication Processes

#95

My favourite stupidity is related to self-service password reset questions. You know the type: "What's your favourite animal?", and other easily-guessed and easily obtained information hackers can use. I always put in some gibberish by mashing the keyboard and make sure to record them somewhere safe just in case I need a password reset. I memorise my password and that should be fine, right? Well, I was overseas with…

The most insane security question I've encountered is on united.com where they have you select your question _and answer_ from a dropdown.

It's true, I tried it out: https://imgur.com/a/cJ51inY

The list of possible answers can be very long. When they don't recognize your device, you select the answer from a subset.

Re: The New Ten-Factor Authentication Processes

#96

My favourite stupidity is related to self-service password reset questions. You know the type: "What's your favourite animal?", and other easily-guessed and easily obtained information hackers can use. I always put in some gibberish by mashing the keyboard and make sure to record them somewhere safe just in case I need a password reset. I memorise my password and that should be fine, right? Well, I was overseas with…

The most insane security question I've encountered is on united.com where they have you select your question _and answer_ from a dropdown.

And the answer’s probabilities are not equally distributed! For example for the color of the house you grew up in, there are clearly most common colors and rare colors. If they asked for house number, it would have been better.

Re: The New Ten-Factor Authentication Processes

#97

Almost all the comments here pertain to the 10-factor authentication mechanism in the title of the article, but the article really is a criticism of the current education system.

it's both. administration/bureaucracy is behind both. university or megacorp they both overcomplicate things. they overextended because there's no real pressure pushing against that extension.

sure, good intentions are pushing for doing more, more inclusivity more security more assessment, more reports, more measurability (to get more fairness), etc.

and since it's hard to start a competing university or ISP or telco or TSA (!)... there's not even the usual push from the market to be resource efficient.

Re: The New Ten-Factor Authentication Processes

#98

Earlier quoted context omitted.

I treat all security questions as if they are just an additional password. I use a password manager and store a random string for each required security question.

Yet even that becomes an social engineering attack vector, if you can talk to a human: “I just put random gibberish in there” is too likely to work.

You could possibly use generated words to prevent that. "tenably-spelt-stall-proxy" shouldn't be considered "random gibberish."

Re: The New Ten-Factor Authentication Processes

#99

My favourite stupidity is related to self-service password reset questions. You know the type: "What's your favourite animal?", and other easily-guessed and easily obtained information hackers can use. I always put in some gibberish by mashing the keyboard and make sure to record them somewhere safe just in case I need a password reset. I memorise my password and that should be fine, right? Well, I was overseas with…

Add them to the Notes field in Bitwarden

Re: The New Ten-Factor Authentication Processes

#100

Earlier quoted context omitted.

The most insane security question I've encountered is on united.com where they have you select your question _and answer_ from a dropdown.

And the answer’s probabilities are not equally distributed! For example for the color of the house you grew up in, there are clearly most common colors and rare colors. If they asked for house number, it would have been better.

Those are not good questions if you still live in the same place you grew up.
Post reply on HN