Live data from Hacker News

Your computer should say what you tell it to say

eff.org

141–150 of 263 posts

Re: Your computer should say what you tell it to say

#141

Earlier quoted context omitted.

> I will no longer be using the bank's website That's a great temporary measure, but once this has rolled out everywhere and is part of standard commercial experiences, are you really willing to completely opt out of online banking because you're not permitted to send fake browser identification? It's a fine philosophical position, but it feels akin to refusing to use public streets because of the existence of survei…

> are you really willing to completely opt out of online banking Sure, why not? It's not like it's a huge sacrifice on my part. It's just a little reduction in convenience. No big deal. > because you're not permitted to send fake browser identification? That's not the issue for me at all. The issue is if sites require me to use specific browsers, to not use specific extensions, to not be able to modify the browsers,…

> It's not like it's a huge sacrifice on my part. It's just a little reduction in convenience. No big deal.

Sure, I get that. I just feel like it's only a little inconvenience now, but in a few years it will be a big one, and so on. After all, the US is _already_ way behind the rest of the developed world in mobile payment/banking tech.

> The issue is if sites require me to use specific browsers, to not use specific extensions, to not be able to modify the browsers, or to adhere to specific requirements in terms of the OS I'm using.

Ah, I didn't think about that angle. That would be pretty draconian. I foresee a shift to dedicated embedded apps for that, like a restricted VM inside of a browser tab. We'll see!

Re: Your computer should say what you tell it to say

#142

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

While I'm willing to believe banks are very security minded in terms of their core infrastructure, banks do not appear to be with regards to their customer access and usually seem to move very slowly to secure that end of things. Hell, many/most of these large institutions seem to still only support SMS for 2FA and even that's a relatively recent introduction to actually mandate. Which is to say, I expect banks to be…

As the parent pointed out, banks don't care about customer access or even customer security per se. They care about not getting fined or accused of not being "as secure as possible." You and I know that using SMS for 2FA is a non-great idea. Banks mostly know it too. The reason they continue to use it is because regulators will not ding them for using it, and there's currently no better alternative that the average muggle customer can handle.

Re: Your computer should say what you tell it to say

#143

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

While I tend to agree, let's temper this a bit.

We're not all condemned to FIPS ciphers everywhere because banks are, and so on.

I'm hopeful there's some option to it, like how you don't need 2FA often until doing something like changing the password

Re: Your computer should say what you tell it to say

#144

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

my experience with banks has been the opposite - they're always a ways behind the rest of the web on security measures. some banks are still rolling out 2fa. and look how horrifically insecure credit cards are. not because they don't care, but because they see technical measures as only a small piece of their overall security strategy, and online access as only a small part of their business that they consider untrus…

As others have noted, banks are governed by (often multiple) regulators, at the local, state/regional, and national levels typically.

As Brian Krebs has noted, on top of the already-oligopic banking sector is an even more ologopic banking-computer-services sector: "What Is Your Bank’s Security Banking On?" (2018).[1] Sadly, the industry is dominated by a small handful of banking platform providers. Four, Fiserv, Jack Henry, FIS, and CSI, serv over 80% of the market. Bank regulators, responding to Krebs, said that "small to mid-sized banks are massively beholden to their platform providers, and many banks simply accept the defaults instead of pushing for stronger alternatives."

This does also suggest that there may be a small number of points of control over which to enact useful change, though of course there's also a concentrated lobbying interest in avoiding or counterinfluencing same.

________________________________

Notes:

1. https://krebsonsecurity.com/2018/03/what-is-your-banks-secur...> (HN: https://news.ycombinator.com/item?id=20203482>)

Re: Your computer should say what you tell it to say

#145

> A handful of companies have established chokepoints between buyers and sellers, performers and audiences, workers and employers, as well as families and communities. When those companies refuse to deal with you, your digital life grinds to a halt This short paragraph summarizes the (ex-ante) improbably unusual situation we have drifted into. The negatively affected stakeholders being enumerated are more or less the…

We need rules that make it easier to transfer data(including addresses), control your own privacy, more compatible options for storing, searching, sorting, ranking, filtering data.

[deleted]

Re: Your computer should say what you tell it to say

#146
post #85

Earlier quoted context omitted.

Also every industry in Canada

The solution in Canada is to break up some of these huge companies. The free market can solve things, but only if there's a free market. When you have 1 or 2 companies, there's no competition.

It's more allowing foreign competition. If you let US (or whoever) telecom into Canada, Rogers Bell and Telus would have to get their act together or die overnight. Same with banking, air travel, etc. Canadas oligarchs have complete regulatory capture so they don't have to worry about being competitive, that's the problem.

Re: Your computer should say what you tell it to say

#147

Earlier quoted context omitted.

While I'm willing to believe banks are very security minded in terms of their core infrastructure, banks do not appear to be with regards to their customer access and usually seem to move very slowly to secure that end of things. Hell, many/most of these large institutions seem to still only support SMS for 2FA and even that's a relatively recent introduction to actually mandate. Which is to say, I expect banks to be…

> I expect banks to be about the very last significant account you use to mandate this technology Unless Google happens to make fat campaign donations or post-office job offers to elected officials who can insure WEI becomes mandated for banks. In the face of this, what banks want won't matter much.

If Google wants to force WEI to become common, all they really have to do is mandate that sites have to implement WEI in order to be listed in their index.

Re: Your computer should say what you tell it to say

#148
post #89

> A handful of companies have established chokepoints between buyers and sellers, performers and audiences, workers and employers, as well as families and communities. When those companies refuse to deal with you, your digital life grinds to a halt This short paragraph summarizes the (ex-ante) improbably unusual situation we have drifted into. The negatively affected stakeholders being enumerated are more or less the…

> as if they already operate effective mind control at systemic scale. If the logical conclusion of your reasoning is a mass mind control conspiracy, you should revisit your assumptions. > somehow they can bully into submission basically the entire universe I don't think anyone is bullying all of society. I think most people just don't care. It's really not that crazy, no mind control involved. Just good old fashione…

If they can kick the former president off his platform they can bully joe schmo off there platform. Whether you agree with the former president, he was in theory the most powerful person on the planet and had to submit to the powers of large tech companies. I think the idea that most people don't care is not a supported or found assumption either rather you just asserted it.

Re: Your computer should say what you tell it to say

#149

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

I work in a bank. Until a year ago, our passwords are 8 characters max, no special characters, upper and lowercase letters are equal. We were running IE7 up until 2 years ago. A huge amount of the business is still organized around sending excel sheets to each other, with no sidechannel validation. The fact that you recieved an excel sheet from some email is treated as proof that it's valid. Last I checked we were also operating an unauthenticated SMTP relay. They will shit on actual security while telling me that I have to run windows on my work laptop because otherwise they can't run their favorite RAT powershell script to recursively unzip every jar on my system to look for log4shell (yes, still).

The same people who instituted and backed these rules and practices are also running the core system for clearing in the national bank of Denmark.

Banks are not secure. They are conservative and political. They will do everything to tell you they are secure. They will make your life hell to uphold their security theater, but it's just a facade. I have no doubt they will implement WEI, but it will not bring security.

Banks do have a pretty good trackrecord of protecting people's money, but they do that through a defense in depth strategy of having a bunch of compliance officers manually reviewing transactions for suspicious activity.

Re: Your computer should say what you tell it to say

#150

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

my experience with banks has been the opposite - they're always a ways behind the rest of the web on security measures. some banks are still rolling out 2fa. and look how horrifically insecure credit cards are. not because they don't care, but because they see technical measures as only a small piece of their overall security strategy, and online access as only a small part of their business that they consider untrus…

A couple of decades back, I worked on middleware applications for banks. So my knowledge is 100% dated and things may have changed.

But back then, bank security was terrible when viewed through the lens of how hard it is to break in and do bad things. On the other hand, bank security was fantastic in terms of being able to detect when this happened and to be able to find the perpetrators.

Post reply on HN