One thing I've found handy is just to have little or no bio information on your accounts. If you absolutely must have bio info on your account, make all the information different from account to account. This way, if a hacker gets your LinkedIn profile, the information there is different than your Facebook info, which is different than your Twitter info, which is different from your. . Imagine a hacker with a handful…
Jb’s story about how he nearly lost his Twitter handle
61–70 of 123 posts
Re: Jb’s story about how he nearly lost his Twitter handle
#62Earlier quoted context omitted.
>Whatever you think of the state of cybersecurity in terms of encryption, implementation, and user-interface (including 2-factor authentication)...it doesn't seem that the protections against social engineering have developed at the same pace as the increasing ease of accessing public records Yep. Around the same time I started using a randomly generated 24 digit alphanumeric password generated with an offline comput…
I am not sure I get this.... Did your brother move into your apartment? Did you imagine a friend? Are you being sarcastic in a way I have missed?
Re: Jb’s story about how he nearly lost his Twitter handle
#63another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.
> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…
I remember the names of exactly two teachers from high school, today, but only because I was discussing something about them with someone else who remembered over Christmas. My mother's maiden name is spelled differently on her birth certificate and death certificate, so I can't tell which one future me might use after forgetting a password.
Recently, I've noticed a trend of having 6 or 8 fixed security questions to choose 2 or 3 from, none of which actually apply to me in a reliable way.
There's really no other solution but to treat them as an additional password field.
Re: Jb’s story about how he nearly lost his Twitter handle
#64Damn, my passwords are crap (some are written in OneNote because forums make me change them every half a year), but then again I don't have any precious online properties besides some websites that I use stronger passwords for. Not like it matters since it looks like social engineering is alive and kicking (as they say, humans are always the weakest link in security). These articles really make me want to set up an a…
Re: Jb’s story about how he nearly lost his Twitter handle
#65- Separate, low-balance checking or similar bank account for "routine payments". Larger balances held in other accounts that cannot be accessed / drawn from through normal channels.
- Separate contact address(es) for distinct and more public interfaces. E.g. I and some friends already have P.O. boxes for this purpose.
- There are other instances/examples, but this is enough while keeping this comment brief.
AND HERE IS AN IMPORTANT POINT: Companies that won't let us do this, or even just make it hard, will become anathema to our own best interests.
THERE ARE LEGITIMATE REASONS I don't want all my services and access consolidated under a single user ID and password or other authentication.
Services that push towards "one true name" and "all services lumped together", are -- from this security perspective -- not in my best interest.
I learned years ago about the value of compartmentalization. It seems that many companies have yet to learn that this is a legitimate concern and feature for their customers.
In the age of electronic recordkeeping and processing, it really is a minimal burden upon a business to support more than one account per customer. Customers have legitimate reasons for doing this. Get over it, and give them what they want and need.
Re: Jb’s story about how he nearly lost his Twitter handle
#66Earlier quoted context omitted.
How would that be exploitable?
If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)
Re: Jb’s story about how he nearly lost his Twitter handle
#67It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before…
Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.
Re: Jb’s story about how he nearly lost his Twitter handle
#68Earlier quoted context omitted.
It’s worth setting up two-factor authentication on any service that supports it: Google, Facebook and Github spring to mind.
Dropbox and app.net also do 2FA. If the service you're using doesn't support it, ask them to implement it. If enough people did it..
Re: Jb’s story about how he nearly lost his Twitter handle
#69Earlier quoted context omitted.
Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.
That's not completely true. If you're in an old Ameritech area in Ohio, pick up the phone, dial '0' and when the Operator comes on, say: "OBT-125, please read number on display." You'll get the NPA-NXX-XXXX read out to you and she'll tell you to have a good day. As of three years ago, you could call any of the embarq/sprint area operators in Ohio/Kentucky and just say, "ID Me." Phone phreaking is still alive, but, it…
Re: Jb’s story about how he nearly lost his Twitter handle
#70Earlier quoted context omitted.
If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)
Why would it not suffice to call yourself on your own cell phone and look at the caller id?