Live data from Hacker News

Your computer should say what you tell it to say

eff.org

241–250 of 263 posts

Re: Your computer should say what you tell it to say

#242

Remember: upvoting the EFF's articles is good, but you (yes, you!) can also donate to them to help with these campaigns!

I had donated to the EFF in the past, but their stance[1] that CDNs/hosted services shouldn't be allowed to choose the customers they are willing work with is not only wrong, it's causes harm[2]. [1] https://www.eff.org/press/releases/international-coalition-r... [2] https://blog.cloudflare.com/kiwifarms-blocked/

>hosted services shouldn't be allowed to choose the customers they are willing work with is not only wrong,

Cool. So since you do think multi-billion dollar companies should be allowed to deny services to a paying customer, I assume if they deny offering their services to gays or blacks, for instance, you are also fine with that? Like, we shouldn't force corporations to do business with anyone...

Re: Your computer should say what you tell it to say

#243

Earlier quoted context omitted.

I work in a bank. Until a year ago, our passwords are 8 characters max, no special characters, upper and lowercase letters are equal. We were running IE7 up until 2 years ago. A huge amount of the business is still organized around sending excel sheets to each other, with no sidechannel validation. The fact that you recieved an excel sheet from some email is treated as proof that it's valid. Last I checked we were al…

> Until a year ago, our passwords are 8 characters max, no special characters, upper and lowercase letters are equal. That’s pretty good. A major Canadian bank until ~2020 had 6 character limit passwords (possibly you could enter more, but only the first six count) and mapped all alpha characters to numbers in groups of 3 (so your assigned telephone banking PIN was just a “hash” of your password). https://news.ycombi…

HSBC in the UK clipped passwords at the first 6 (maybe 8, I forget) characters.

This is the problem with having old mainframes somewhere in the backend. Their rules bubble up even where it doesn't make sense.

Re: Your computer should say what you tell it to say

#244

Earlier quoted context omitted.

My health insurance portal (Aetna, no I am not above naming and shaming) did something annoying. When I signed up I used a randomly generated three-word passphrase from my password manager. It was around 32 characters or something. They have the fun pattern of logging you out of your account whenever you are inactive. A bit excessive for a health insurance provider imo, but whatever. So I tried to login and guess wha…

Heh, I had a health insurance portal that when you changed your password with their mobile app, it would let you use all the special characters. However the web app blocked (or stripped) those characters out, meaning you couldn't log in to the web app because it literally wouldn't let you type your password. Every so often the mobile app forced re-auth, and it redirected you to the web version where putting in your p…

Yes, I really dislike those companies that spend so much effort blocking pasting into the second password field when filling them out so they break password managers.

Luckily it's normally easy enough to edit the tags on the text box but even so, this shouldn't be necessary.

Fucking BT.

Re: Your computer should say what you tell it to say

#245

Earlier quoted context omitted.

As the parent pointed out, banks don't care about customer access or even customer security per se. They care about not getting fined or accused of not being "as secure as possible." You and I know that using SMS for 2FA is a non-great idea. Banks mostly know it too. The reason they continue to use it is because regulators will not ding them for using it , and there's currently no better alternative that the average…

One of the banks I work with had 2FA fobs since the beginning of 2000s. Now they have the same "fob" as an app in the phone, and using it is mandatory IIRC. Most banks lock your phone access to your IMEI + phone model + some phone specific data, so people knowing your details can't login without your phone. Web side needs 2FA or special activation depending on the bank. Forgot your password? You need your biometric I…

I think the parent posts meant that whoever reviews your banks 2FA should say "that is good" would also look at the SMS system and say "that is good".

If they are only doing it to tick compliance boxes then there is probably not much motivation to do it better. Those systems are security theatre.

Re: Your computer should say what you tell it to say

#246
post #148

Earlier quoted context omitted.

If they can kick the former president off his platform they can bully joe schmo off there platform. Whether you agree with the former president, he was in theory the most powerful person on the planet and had to submit to the powers of large tech companies. I think the idea that most people don't care is not a supported or found assumption either rather you just asserted it.

>he was in theory the most powerful person on the planet You need to provide a practical definition of "most powerful" before your phrase can be evaluated.

He had the ability to give the order to start thermonuclear war and end humanity... He had the ability to radically tariffing and regulatory execution in America. I argue that it something that a more precise definition is excels from but I also think a more robust definition isn't really required to demonstrate the point. I'd felt that the president of the US is extremely powerful more so either one of us most likely

Re: Your computer should say what you tell it to say

#247
post #148

Earlier quoted context omitted.

If they can kick the former president off his platform they can bully joe schmo off there platform. Whether you agree with the former president, he was in theory the most powerful person on the planet and had to submit to the powers of large tech companies. I think the idea that most people don't care is not a supported or found assumption either rather you just asserted it.

You are demonstrating that power is distributed, which many consider a good thing. Checks and balances and all that. What would be worse than the media having too much control is the media having no control.

Absolutely but the idea that you can basically "deperson" someone's voice without any review in the case of most large social media platforms seems more like a concentration of power than a distribution of. In this context its against a president so its a check but in the context of Joe Schemo its just an abuse you have to take. Regardless of if it is the CCP or Social Media Companies censoring its still censoring

Re: Your computer should say what you tell it to say

#248

Earlier quoted context omitted.

One of the banks I work with had 2FA fobs since the beginning of 2000s. Now they have the same "fob" as an app in the phone, and using it is mandatory IIRC. Most banks lock your phone access to your IMEI + phone model + some phone specific data, so people knowing your details can't login without your phone. Web side needs 2FA or special activation depending on the bank. Forgot your password? You need your biometric I…

I think the parent posts meant that whoever reviews your banks 2FA should say "that is good" would also look at the SMS system and say "that is good". If they are only doing it to tick compliance boxes then there is probably not much motivation to do it better. Those systems are security theatre.

Yes, I understood what the parent post tried to say, and just wanted to provide a counter example which is not a security theater in its nature.

Ah, also the same bank doesn't send SMS anmymore. Everything arrives to their app. Only they fallback to SMS if the app fails to acknowledge receiving the notification, which happens once a year?

Also, banks do not mail financial information by default to prevent wiretapping by 3rd parties.

Re: Your computer should say what you tell it to say

#249

Earlier quoted context omitted.

> I expect banks to be about the very last significant account you use to mandate this technology Unless Google happens to make fat campaign donations or post-office job offers to elected officials who can insure WEI becomes mandated for banks. In the face of this, what banks want won't matter much.

If Google wants to force WEI to become common, all they really have to do is mandate that sites have to implement WEI in order to be listed in their index.

I absolutely agree. I was making the case for how Google could manipulate a theoretically-resistant banking industry.

I get banking is regulated from a variety of directions. However, the path of lobbyist influence->federal manipulation is so well worn it impacts many (probably most) exertions of power.

Re: Your computer should say what you tell it to say

#250

Earlier quoted context omitted.

If Google wants to force WEI to become common, all they really have to do is mandate that sites have to implement WEI in order to be listed in their index.

But that would be fuel for another antitrust case.

Are you saying the outcome of previous antitrust cases (especially against big tech) hurt those businesses sufficiently that they act as a deterrent? It doesn't look that way from my position here in the peanut gallery.
Post reply on HN