I think a lot of it comes down to this: "4. Some of the biggest companies in the world have security that is only as good as a minimum-wage phone support worker who has the power to reset your account. And they have valid business reasons for giving them this power."
It could be greatly mitigated by automating that power more. E.g., "No problem, I can reset your password! The system will automatically contact your registered phone number and email address -- if you confirm both, it resets now, and if you can't, it will send the reset to your new email 3 days from now."
Jb’s story about how he nearly lost his Twitter handle
51–60 of 123 posts
Re: Jb’s story about how he nearly lost his Twitter handle
#52another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.
> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…
These security questions are made for us old farts, for days when there was no Internet like today and there were none of this information available online.
Re: Jb’s story about how he nearly lost his Twitter handle
#53Earlier quoted context omitted.
At the bottom in tiny text it says: "Published January 29, 2014" Also, in the source:
That is when it was published, but the text gives no indication if the events happened yesterday or 12 months ago. It's useful to know if these abysmal practices are still current or not at Apple/Amazon/etc.
Re: Jb’s story about how he nearly lost his Twitter handle
#54Jesus fucking christ. Stop making websites accept anything other than a username+password/token for authentication, and this kind of retarded shit would never happen. It's somehow still the status quo to make backdoors to recover your account incase you lock yourself out, which is why things like this happen all the time. You get what you deserve.
This is great in theory, but in practice your regular customers are going to lose/mix up their usernames and passwords all the time. They need some kind of back door to recover their access (because honestly, even for the responsible and tech-savvy users, sometimes sh!t happens... e.g., my password manager generated a new password but my laptop crashed before I could save it), and they assume there will be a way to r…
A) Customers locking themselves out of accounts
B) Accounts being stolen by identity theft
Pick one.
> I'm sure you could tell your customers "you get what you deserve", but not if you want them to remain customers.
I kill people for a living. You can tell me I could stop killing people for a living but then I'd stop having customers. Thus it's impractical to stop killing people.
Re: Jb’s story about how he nearly lost his Twitter handle
#55> He then called Amazon with what little information he had gained and cried that he had lost his password and didn’t have access to that email address anymore. The representative caved and reset the password over the phone giving him full access to my Amazon account. His plan was to then gain as much information he could with Amazon (last four of credit card numbers, current and previous addresses, etc…) and use tha…
>Whatever you think of the state of cybersecurity in terms of encryption, implementation, and user-interface (including 2-factor authentication)...it doesn't seem that the protections against social engineering have developed at the same pace as the increasing ease of accessing public records Yep. Around the same time I started using a randomly generated 24 digit alphanumeric password generated with an offline comput…
Did your brother move into your apartment? Did you imagine a friend? Are you being sarcastic in a way I have missed?
Re: Jb’s story about how he nearly lost his Twitter handle
#56Earlier quoted context omitted.
This is great in theory, but in practice your regular customers are going to lose/mix up their usernames and passwords all the time. They need some kind of back door to recover their access (because honestly, even for the responsible and tech-savvy users, sometimes sh!t happens... e.g., my password manager generated a new password but my laptop crashed before I could save it), and they assume there will be a way to r…
Gee, you're going to have a hard time with bitcoin, hidden tor services, etc. A) Customers locking themselves out of accounts B) Accounts being stolen by identity theft Pick one. > I'm sure you could tell your customers "you get what you deserve", but not if you want them to remain customers. I kill people for a living. You can tell me I could stop killing people for a living but then I'd stop having customers. Thus…
Re: Jb’s story about how he nearly lost his Twitter handle
#57another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.
> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…
Companies should allow security-conscious customers the ability to opt out of this attack vector. Alternatively, just use another 20 character randomly generated string for each of the answers.
Re: Jb’s story about how he nearly lost his Twitter handle
#58another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.
> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…
Re: Jb’s story about how he nearly lost his Twitter handle
#59It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before…
Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.
If you're in an old Ameritech area in Ohio, pick up the phone, dial '0' and when the Operator comes on, say:
"OBT-125, please read number on display."
You'll get the NPA-NXX-XXXX read out to you and she'll tell you to have a good day. As of three years ago, you could call any of the embarq/sprint area operators in Ohio/Kentucky and just say, "ID Me."
Phone phreaking is still alive, but, it's not as common as it once was.
Re: Jb’s story about how he nearly lost his Twitter handle
#60These articles really make me want to set up an automated system that would monitor any password reset events (and other suspicious activity) and automatically change those passwords itself and/or notify me by sms...