Live data from Hacker News

The New Ten-Factor Authentication Processes

mcsweeneys.net

101–107 of 107 posts

Re: The New Ten-Factor Authentication Processes

#101

Earlier quoted context omitted.

> You know the type: "What's your favourite animal?", and other easily-guessed and easily obtained information hackers can use. > I always put in some gibberish by mashing the keyboard and make sure to record them somewhere safe just in case I need a password reset. I memorise my password and that should be fine, right? But then you have to trust that "somewhere safe" is actually as safe as you think it is. One alter…

>One alternative is to use them like mnemonic code phrases. So perhaps your answer to "What's your favourite animal?" is not really an animal, but maybe Cthulhu, so maybe the answer would be "Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn" I'd go further than that and use stuff like that for actual passwords, but with a twist. Using that sort of thing for such questions is good, but take something you know well,…

Finally make those eggcorns useful!

In linguistics, an eggcorn is an idiosyncratic substitution of a word or phrase for a word or words that sound similar or identical in the speaker's dialect. The new phrase introduces a meaning that is different from the original but plausible in the same context, such as "old-timers' disease" for "Alzheimer's disease".[1] An eggcorn can be described as an intra-lingual phono-semantic matching, a matching in which the intended word and substitute are from the same language. Together with other types of same-sounding phrases, eggcorns are sometimes also referred to "oronyms".

https://en.m.wikipedia.org/wiki/Eggcorn

Re: The New Ten-Factor Authentication Processes

#102
post #98

Earlier quoted context omitted.

Yet even that becomes an social engineering attack vector, if you can talk to a human: “I just put random gibberish in there” is too likely to work.

You could possibly use generated words to prevent that. "tenably-spelt-stall-proxy" shouldn't be considered "random gibberish."

Shouldn't, but it all depends on the training and awareness of the person on the phone. Instead of "random gibberish" the attacker could just say "random words", or, if they didn't know which strategy you used, "random stuff".

Re: The New Ten-Factor Authentication Processes

#103

Earlier quoted context omitted.

They can't scrape the clipboard because of autofill, and they can't record the screen because passwords appear as ******.

> passwords appear as hunter2. You should be careful about copy pasting your password on the internet.

Huh? That’s not what I wrote...

Re: The New Ten-Factor Authentication Processes

#107
post #61

People who care about user experience hardy ever talk to people who care about security in large organizations. That's how we end up with experiences like this. Ring (Amazon) made me call them to reset my two-factor app sync. They asked me to send a bill to the address of my home via my email as a proof that this is really me and not just someone who have my password and access to my email. I asked what's the point o…

Though that approach is flawed, at least they stuck to their script, i.e., resisted social engineering.
Post reply on HN