Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

61–70 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#61

One thing I've found handy is just to have little or no bio information on your accounts. If you absolutely must have bio info on your account, make all the information different from account to account. This way, if a hacker gets your LinkedIn profile, the information there is different than your Facebook info, which is different than your Twitter info, which is different from your. . Imagine a hacker with a handful…

Have you been the target of hacking attempts? This sounds the opposite of handy, so I'd be interested to know how well it actually works. Not sure how well it would pay but I'd be interested in a service that attempts to steal your identity in this way, and then tells you what you can do to plug the vulnerabilities.

Re: Jb’s story about how he nearly lost his Twitter handle

#62

Earlier quoted context omitted.

>Whatever you think of the state of cybersecurity in terms of encryption, implementation, and user-interface (including 2-factor authentication)...it doesn't seem that the protections against social engineering have developed at the same pace as the increasing ease of accessing public records Yep. Around the same time I started using a randomly generated 24 digit alphanumeric password generated with an offline comput…

I am not sure I get this.... Did your brother move into your apartment? Did you imagine a friend? Are you being sarcastic in a way I have missed?

third (sarcasm). I don't think the bar with social engineering has moved NEARLY as much as cyber security has. It's practically impossible to keep a computer secure, but very easy not to be duped by strangers on a social level.

Re: Jb’s story about how he nearly lost his Twitter handle

#63
post #36
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…

Security questions are already useless. What's my first pet's name? Depending on the day, I might have any of three or four answers; I'm unlikely to remember which pet was first, 30-35 years ago, even if I think I can, since if you ask me in a month, I might be just as confident the other way! Given the uncertainty, I might well decide that the best answer is a later pet I remember better, but then which one is that?

I remember the names of exactly two teachers from high school, today, but only because I was discussing something about them with someone else who remembered over Christmas. My mother's maiden name is spelled differently on her birth certificate and death certificate, so I can't tell which one future me might use after forgetting a password.

Recently, I've noticed a trend of having 6 or 8 fixed security questions to choose 2 or 3 from, none of which actually apply to me in a reliable way.

There's really no other solution but to treat them as an additional password field.

Re: Jb’s story about how he nearly lost his Twitter handle

#64
post #60

Damn, my passwords are crap (some are written in OneNote because forums make me change them every half a year), but then again I don't have any precious online properties besides some websites that I use stronger passwords for. Not like it matters since it looks like social engineering is alive and kicking (as they say, humans are always the weakest link in security). These articles really make me want to set up an a…

It really is worth it. It is a pain to first set up and change every password to some random string (which most vaults will generate for you), but after that it's smooth sailing more or less. I recommend LastPass, it's free (unless you want the Android app, but even then the premium account is super cheap).

Re: Jb’s story about how he nearly lost his Twitter handle

#65
We are going to have to learn to -- effectively -- use compartmentalization, ourselves. (Us technophiles, certainly, but also the "greater masses".)

- Separate, low-balance checking or similar bank account for "routine payments". Larger balances held in other accounts that cannot be accessed / drawn from through normal channels.

- Separate contact address(es) for distinct and more public interfaces. E.g. I and some friends already have P.O. boxes for this purpose.

- There are other instances/examples, but this is enough while keeping this comment brief.

AND HERE IS AN IMPORTANT POINT: Companies that won't let us do this, or even just make it hard, will become anathema to our own best interests.

THERE ARE LEGITIMATE REASONS I don't want all my services and access consolidated under a single user ID and password or other authentication.

Services that push towards "one true name" and "all services lumped together", are -- from this security perspective -- not in my best interest.

I learned years ago about the value of compartmentalization. It seems that many companies have yet to learn that this is a legitimate concern and feature for their customers.

In the age of electronic recordkeeping and processing, it really is a minimal burden upon a business to support more than one account per customer. Customers have legitimate reasons for doing this. Get over it, and give them what they want and need.

Re: Jb’s story about how he nearly lost his Twitter handle

#66
post #35

Earlier quoted context omitted.

How would that be exploitable?

If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)

Why would it not suffice to call yourself on your own cell phone and look at the caller id?

Re: Jb’s story about how he nearly lost his Twitter handle

#67
post #30
post #19

It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before…

Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.

One could always call one of these instead: https://en.wikipedia.org/wiki/Automatic_number_announcement_...

Re: Jb’s story about how he nearly lost his Twitter handle

#68
post #9

Earlier quoted context omitted.

It’s worth setting up two-factor authentication on any service that supports it: Google, Facebook and Github spring to mind.

Dropbox and app.net also do 2FA. If the service you're using doesn't support it, ask them to implement it. If enough people did it..

So does Namecheap.

Re: Jb’s story about how he nearly lost his Twitter handle

#69
post #59
post #30

Earlier quoted context omitted.

Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.

That's not completely true. If you're in an old Ameritech area in Ohio, pick up the phone, dial '0' and when the Operator comes on, say: "OBT-125, please read number on display." You'll get the NPA-NXX-XXXX read out to you and she'll tell you to have a good day. As of three years ago, you could call any of the embarq/sprint area operators in Ohio/Kentucky and just say, "ID Me." Phone phreaking is still alive, but, it…

What does 'OBT-125' signify/mean?

Re: Jb’s story about how he nearly lost his Twitter handle

#70
post #66
post #35

Earlier quoted context omitted.

If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)

Why would it not suffice to call yourself on your own cell phone and look at the caller id?

Probably for the same reason you wouldn't want to ping your personal webpage from a remote computer you just hacked.
Post reply on HN