Live data from Hacker News

What is the origin of passwords submitted to honeypots?

isc.sans.edu

31–40 of 44 posts

Re: What is the origin of passwords submitted to honeypots?

#31
post #8

Passwords should be dead soon and this article should be irrelevant soon after. PSA: For most basic and routine websites/apps of low-value, please, please use the FaceID/TouchID protected platform authenticators for passwordless authentication. And for those archaic sites that still insist on passwords (why? tell them about passwordless by writing feedback/app reviews), use the platform built-in password managers. Do…

Right, and what you recommend in those situations where, due to unusual circumstances (flat battery, whatever), you need to access to, say, your online banking or airline site or email or whatever using another device that would have no way of knowing who you are? If there's a way to access a web-based password manager securely from any device, then surely there's a way to access whatever application you actually need access to securely too...

FWIW I use a password manager of sorts, but only to remember "hints". Once I see the hint I can reliably recall what the full password is, but there's no way reasonable way for someone else to do so. It's only passwords I use very rarely I even really need such hints for.

Re: What is the origin of passwords submitted to honeypots?

#32

Earlier quoted context omitted.

I didn’t know Jason Bourne posted on HN. In all seriousness, where’s the threat of someone taking extremely high resolution scans of your iris unless you are truly rich/powerful/connected.

Fingerprint scanning is going mainstream, heres a post about Amazon using palm scans on point of sale systems [1]. It seems reasonable that point of sale systems will get hacked or skimmers will get installed (common problems impacting normal people today). The current fix is to issue a new card. Unfortunately, you cannot have a new finger/palm print issued, so the threat appears unmitigated. [1] https://www.bbc.co.u…

[deleted]

Re: What is the origin of passwords submitted to honeypots?

#33
post #23

Earlier quoted context omitted.

Define soon. Passwords, for all their annoyances, will probably be around for a long time. While they are not brilliant at anything, they are good enough on many dimensions. Some disadvantages of the things you mention are: * They don't require specialised hardware * They don't require complicated recovery mechanisms if that hardware is lost, stolen or broken. * Arguably, biometrics should not be used for authenticat…

My bank dropped using passwords back in july. Now all that protects my account is a 5 digit PIN and SMS, and you can reset the pin via SMS. I'm glad financial companies hire security minded folks.

I suspect that what's supposed to be going on there is that what protects your account is law enforcement and the fact that financial transactions are traceable.

Re: What is the origin of passwords submitted to honeypots?

#34
post #8

Passwords should be dead soon and this article should be irrelevant soon after. PSA: For most basic and routine websites/apps of low-value, please, please use the FaceID/TouchID protected platform authenticators for passwordless authentication. And for those archaic sites that still insist on passwords (why? tell them about passwordless by writing feedback/app reviews), use the platform built-in password managers. Do…

I think I would drop any service that required me to go to WebAuthn.

Re: What is the origin of passwords submitted to honeypots?

#35

Earlier quoted context omitted.

You can be scammed into entering your password into a random textbox and then relayed on the actual website/app. This is too basic. In case of FaceID/TouchID, the acquiring platform (your mobile phone) has secure device binding and FaceID/TouchID is a local authenticator on that device to use that secure device binding to authenticate. If FaceID/TouchID becomes fakeable, we will move on to some other more secure loca…

> you have a rich multi-sensor mobile device as your authenticator YOU, a relatively wealthy programmer/middle manager living in a first-world country, have access to such a device. Ever think about who you're disenfranchising with tech like this? Or to whom you're ceding socioeconomic power and political influence?

Using open-standards based passwordless auth is not ceding control to anyone.

Btw, your assumptions about me are wrong. You don't know anything about me. So don't make it personal.

Re: What is the origin of passwords submitted to honeypots?

#37

Earlier quoted context omitted.

> you have a rich multi-sensor mobile device as your authenticator YOU, a relatively wealthy programmer/middle manager living in a first-world country, have access to such a device. Ever think about who you're disenfranchising with tech like this? Or to whom you're ceding socioeconomic power and political influence?

Using open-standards based passwordless auth is not ceding control to anyone. Btw, your assumptions about me are wrong. You don't know anything about me. So don't make it personal.

[deleted]

Re: What is the origin of passwords submitted to honeypots?

#38
post #7

It's an interesting optimization problem for the attacker. The most common passwords are problematic. They will frequently work, but they will work for the other guy, too. So then the question is "how do you pull up the ladder?" Changing the password is simple, but likely to get the machine reimaged. Looking at the login history would give an allowlist of subnets, which can be used to deny other attackers access, but…

> So then the question is "how do you pull up the ladder?" I've never heard that metaphor before, but it's a good one. Thanks.

I've never seen it used in this context; it usually is used in reference to a social program (i.e. you benefitted from something and then advocate for it to be abolished).

Re: What is the origin of passwords submitted to honeypots?

#39
post #33
post #23

Earlier quoted context omitted.

My bank dropped using passwords back in july. Now all that protects my account is a 5 digit PIN and SMS, and you can reset the pin via SMS. I'm glad financial companies hire security minded folks.

I suspect that what's supposed to be going on there is that what protects your account is law enforcement and the fact that financial transactions are traceable.

Yeah, her bank has stationed a cop to stand at every website login and proactively arrest hackers before they can get at her money.

Re: What is the origin of passwords submitted to honeypots?

#40
post #23

Earlier quoted context omitted.

Define soon. Passwords, for all their annoyances, will probably be around for a long time. While they are not brilliant at anything, they are good enough on many dimensions. Some disadvantages of the things you mention are: * They don't require specialised hardware * They don't require complicated recovery mechanisms if that hardware is lost, stolen or broken. * Arguably, biometrics should not be used for authenticat…

My bank dropped using passwords back in july. Now all that protects my account is a 5 digit PIN and SMS, and you can reset the pin via SMS. I'm glad financial companies hire security minded folks.

This is satire, right?
Post reply on HN