Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

71–80 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#71
post #36

Earlier quoted context omitted.

> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…

Security questions are already useless. What's my first pet's name? Depending on the day, I might have any of three or four answers; I'm unlikely to remember which pet was first, 30-35 years ago, even if I think I can , since if you ask me in a month, I might be just as confident the other way! Given the uncertainty, I might well decide that the best answer is a later pet I remember better, but then which one is that…

Strictly speaking, they do have one benefit. If someone steals your password, there is really no way to know. If they reset your account with a security question, you'll know as soon as you access.

Still pretty terrible, though.

Re: Jb’s story about how he nearly lost his Twitter handle

#72

Earlier quoted context omitted.

I am not sure I get this.... Did your brother move into your apartment? Did you imagine a friend? Are you being sarcastic in a way I have missed?

third (sarcasm). I don't think the bar with social engineering has moved NEARLY as much as cyber security has. It's practically impossible to keep a computer secure, but very easy not to be duped by strangers on a social level.

What if the people getting duped to give away your account are minimum wage call centre workers who'd probably like you off the phone ASAP? You're a genius who'd never get scammed like this, fine, but you're not the weakest link here.

Re: Jb’s story about how he nearly lost his Twitter handle

#73
post #70
post #66

Earlier quoted context omitted.

Why would it not suffice to call yourself on your own cell phone and look at the caller id?

Probably for the same reason you wouldn't want to ping your personal webpage from a remote computer you just hacked.

OK, so get yourself a burner and call that. One way or another, this does not seem like a hard problem.

Re: Jb’s story about how he nearly lost his Twitter handle

#74
The problem is that different companies have different protocols on what information they use to identify users, etc, and hackers are getting smart enough to connect various partial information to get full information on a user.

Every single customer-facing company needs to have STANDARDIZED security/information protocols. This includes taking in same information, and only giving out the same information. This should solve this problem.

Re: Jb’s story about how he nearly lost his Twitter handle

#75
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

Security questions is one of the stupidest ideas in the so-called "security" industry. This causes so much information leakage and confusion and doesn't really solve anything. They really need to be removed from every company's security protocol.

Re: Jb’s story about how he nearly lost his Twitter handle

#76
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

I always wondered if phone CSRs use those to authenticate a caller. I wasn't looking forward to reading out a 40-digit string of nonsense over the phone.

Good to know all they require is that you can guess a 2-digit number instead...

Re: Jb’s story about how he nearly lost his Twitter handle

#77
post #44

Earlier quoted context omitted.

It could be greatly mitigated by automating that power more. E.g., "No problem, I can reset your password! The system will automatically contact your registered phone number and email address -- if you confirm both, it resets now, and if you can't, it will send the reset to your new email 3 days from now."

Now all an attacker has to do is wait for me to go on a cruise, or camping trip, or basically take any action which means I'm out of communication for a week or more.

It's a change from near-zero security like now, to having to know your routine, travel, and communication plans. Perfect? No, but what is?

Re: Jb’s story about how he nearly lost his Twitter handle

#79
post #44

Earlier quoted context omitted.

It could be greatly mitigated by automating that power more. E.g., "No problem, I can reset your password! The system will automatically contact your registered phone number and email address -- if you confirm both, it resets now, and if you can't, it will send the reset to your new email 3 days from now."

Now all an attacker has to do is wait for me to go on a cruise, or camping trip, or basically take any action which means I'm out of communication for a week or more.

so that's better than before, right?

Re: Jb’s story about how he nearly lost his Twitter handle

#80
post #76
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

I always wondered if phone CSRs use those to authenticate a caller. I wasn't looking forward to reading out a 40-digit string of nonsense over the phone. Good to know all they require is that you can guess a 2-digit number instead...

Alice (telco) at one point required the password I used on the website to identify me on the phone. Quite sensible as authentication/identification (though it requires the password to be stored in plain text somewhere, something I don’t really care about) in theory and reading out aPua6EG8H0nB6UIxOwsQQeVYUF71NRQ9AkBqg4rujU8vAcLMnG is not all that hard.
Post reply on HN