Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

51–60 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#51
post #44
post #6

I think a lot of it comes down to this: "4. Some of the biggest companies in the world have security that is only as good as a minimum-wage phone support worker who has the power to reset your account. And they have valid business reasons for giving them this power."

It could be greatly mitigated by automating that power more. E.g., "No problem, I can reset your password! The system will automatically contact your registered phone number and email address -- if you confirm both, it resets now, and if you can't, it will send the reset to your new email 3 days from now."

Now all an attacker has to do is wait for me to go on a cruise, or camping trip, or basically take any action which means I'm out of communication for a week or more.

Re: Jb’s story about how he nearly lost his Twitter handle

#52
post #36
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…

The security questions in its current implementation are useless anyhow. Because all those pieces of information are exploitable by your social life these days. "What's the name of your first math teacher" — Take a look into the years schoolbook, which are online.

These security questions are made for us old farts, for days when there was no Internet like today and there were none of this information available online.

Re: Jb’s story about how he nearly lost his Twitter handle

#53
post #40

Earlier quoted context omitted.

At the bottom in tiny text it says: "Published January 29, 2014" Also, in the source:

That is when it was published, but the text gives no indication if the events happened yesterday or 12 months ago. It's useful to know if these abysmal practices are still current or not at Apple/Amazon/etc.

oh right, i just assumed it happened recently

Re: Jb’s story about how he nearly lost his Twitter handle

#54
post #43
post #38

Jesus fucking christ. Stop making websites accept anything other than a username+password/token for authentication, and this kind of retarded shit would never happen. It's somehow still the status quo to make backdoors to recover your account incase you lock yourself out, which is why things like this happen all the time. You get what you deserve.

This is great in theory, but in practice your regular customers are going to lose/mix up their usernames and passwords all the time. They need some kind of back door to recover their access (because honestly, even for the responsible and tech-savvy users, sometimes sh!t happens... e.g., my password manager generated a new password but my laptop crashed before I could save it), and they assume there will be a way to r…

Gee, you're going to have a hard time with bitcoin, hidden tor services, etc.

A) Customers locking themselves out of accounts

B) Accounts being stolen by identity theft

Pick one.

> I'm sure you could tell your customers "you get what you deserve", but not if you want them to remain customers.

I kill people for a living. You can tell me I could stop killing people for a living but then I'd stop having customers. Thus it's impractical to stop killing people.

Re: Jb’s story about how he nearly lost his Twitter handle

#55
post #12

> He then called Amazon with what little information he had gained and cried that he had lost his password and didn’t have access to that email address anymore. The representative caved and reset the password over the phone giving him full access to my Amazon account. His plan was to then gain as much information he could with Amazon (last four of credit card numbers, current and previous addresses, etc…) and use tha…

>Whatever you think of the state of cybersecurity in terms of encryption, implementation, and user-interface (including 2-factor authentication)...it doesn't seem that the protections against social engineering have developed at the same pace as the increasing ease of accessing public records Yep. Around the same time I started using a randomly generated 24 digit alphanumeric password generated with an offline comput…

I am not sure I get this....

Did your brother move into your apartment? Did you imagine a friend? Are you being sarcastic in a way I have missed?

Re: Jb’s story about how he nearly lost his Twitter handle

#56
post #54
post #43

Earlier quoted context omitted.

This is great in theory, but in practice your regular customers are going to lose/mix up their usernames and passwords all the time. They need some kind of back door to recover their access (because honestly, even for the responsible and tech-savvy users, sometimes sh!t happens... e.g., my password manager generated a new password but my laptop crashed before I could save it), and they assume there will be a way to r…

Gee, you're going to have a hard time with bitcoin, hidden tor services, etc. A) Customers locking themselves out of accounts B) Accounts being stolen by identity theft Pick one. > I'm sure you could tell your customers "you get what you deserve", but not if you want them to remain customers. I kill people for a living. You can tell me I could stop killing people for a living but then I'd stop having customers. Thus…

Oh wait, I forgot this is HN, where conforming to retarded dogma is the only way to be cool.

Re: Jb’s story about how he nearly lost his Twitter handle

#57
post #36
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…

"Security questions" are already worse than useless, because they provide an easier attack vector (if they are answered honestly). Things like your pet's name and the street you lived on as a child are easily obtainable online.

Companies should allow security-conscious customers the ability to opt out of this attack vector. Alternatively, just use another 20 character randomly generated string for each of the answers.

Re: Jb’s story about how he nearly lost his Twitter handle

#58
post #36
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…

Useless for the intended purpose, but when you login to your bank's website from a different IP (or something similar) and it triggers the security question - then you have it without making it something that someone else can figure out.

Re: Jb’s story about how he nearly lost his Twitter handle

#59
post #30
post #19

It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before…

Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.

That's not completely true.

If you're in an old Ameritech area in Ohio, pick up the phone, dial '0' and when the Operator comes on, say:

"OBT-125, please read number on display."

You'll get the NPA-NXX-XXXX read out to you and she'll tell you to have a good day. As of three years ago, you could call any of the embarq/sprint area operators in Ohio/Kentucky and just say, "ID Me."

Phone phreaking is still alive, but, it's not as common as it once was.

Re: Jb’s story about how he nearly lost his Twitter handle

#60
Damn, my passwords are crap (some are written in OneNote because forums make me change them every half a year), but then again I don't have any precious online properties besides some websites that I use stronger passwords for. Not like it matters since it looks like social engineering is alive and kicking (as they say, humans are always the weakest link in security).

These articles really make me want to set up an automated system that would monitor any password reset events (and other suspicious activity) and automatically change those passwords itself and/or notify me by sms...

Post reply on HN