Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

81–90 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#81

Earlier quoted context omitted.

I am not sure I get this.... Did your brother move into your apartment? Did you imagine a friend? Are you being sarcastic in a way I have missed?

third (sarcasm). I don't think the bar with social engineering has moved NEARLY as much as cyber security has. It's practically impossible to keep a computer secure, but very easy not to be duped by strangers on a social level.

People get duped by strangers all the time. It's much easier to find out someone's childhood pet name than to, say, break TLS. A lot faster and usually less conspicuous too.

Hell, getting the last four digits of someone's credit card number might be as simple as pulling a receipt they threw away out of the trash.

Re: Jb’s story about how he nearly lost his Twitter handle

#82
post #56
post #54

Earlier quoted context omitted.

Gee, you're going to have a hard time with bitcoin, hidden tor services, etc. A) Customers locking themselves out of accounts B) Accounts being stolen by identity theft Pick one. > I'm sure you could tell your customers "you get what you deserve", but not if you want them to remain customers. I kill people for a living. You can tell me I could stop killing people for a living but then I'd stop having customers. Thus…

Oh wait, I forgot this is HN, where conforming to retarded dogma is the only way to be cool.

Please impart more wisdom in your lovely obnoxious raging nerd idealist way. It's very unusual to find in tech circles!

Re: Jb’s story about how he nearly lost his Twitter handle

#83
post #69
post #59

Earlier quoted context omitted.

That's not completely true. If you're in an old Ameritech area in Ohio, pick up the phone, dial '0' and when the Operator comes on, say: "OBT-125, please read number on display." You'll get the NPA-NXX-XXXX read out to you and she'll tell you to have a good day. As of three years ago, you could call any of the embarq/sprint area operators in Ohio/Kentucky and just say, "ID Me." Phone phreaking is still alive, but, it…

What does 'OBT-125' signify/mean?

I'm guessing OBT is Ohio Bell Telecom, don't know about 125.

Re: Jb’s story about how he nearly lost his Twitter handle

#84
post #39
post #35

Earlier quoted context omitted.

If you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)

If they're relying on such information for security, they aren't secure in the first place.

They don't have to be "relying" on it to use it.

If you treat security like a mathematical problem [1] with no grey areas, you are going to reject almost every security measure and say "that would only give users a false sense of security."

Just about all security measures can be worked around by a determined attacker. That doesn't mean you stop using them.

The linked page says to hide your whois information. This is surely security through obscurity. Yet it can vastly reduce the number of reset emails you get.

[1] You should treat crypto like a mathematical problem.

Re: Jb’s story about how he nearly lost his Twitter handle

#85
post #36

Earlier quoted context omitted.

> and save that (along with the question title) in your (properly backed up!) password safe. To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally…

Security questions are already useless. What's my first pet's name? Depending on the day, I might have any of three or four answers; I'm unlikely to remember which pet was first, 30-35 years ago, even if I think I can , since if you ask me in a month, I might be just as confident the other way! Given the uncertainty, I might well decide that the best answer is a later pet I remember better, but then which one is that…

I've run into security questions where there were character limits on the answer. "Between 3 and 20 characters, no numbers." The worst of all possible worlds!

Re: Jb’s story about how he nearly lost his Twitter handle

#86
post #54
post #43

Earlier quoted context omitted.

This is great in theory, but in practice your regular customers are going to lose/mix up their usernames and passwords all the time. They need some kind of back door to recover their access (because honestly, even for the responsible and tech-savvy users, sometimes sh!t happens... e.g., my password manager generated a new password but my laptop crashed before I could save it), and they assume there will be a way to r…

Gee, you're going to have a hard time with bitcoin, hidden tor services, etc. A) Customers locking themselves out of accounts B) Accounts being stolen by identity theft Pick one. > I'm sure you could tell your customers "you get what you deserve", but not if you want them to remain customers. I kill people for a living. You can tell me I could stop killing people for a living but then I'd stop having customers. Thus…

Once again proving my point that the biggest impediment to Bitcoin is the Bitcoin community.

Re: Jb’s story about how he nearly lost his Twitter handle

#87
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

I like how Yahoo suddenly decided to make their "security questions" a secondary password. I have no idea what I answered over a decade ago, but I can no longer log into my account despite them acknowledging my password to be correct.

Where's the "reset security question" option...

Re: Jb’s story about how he nearly lost his Twitter handle

#88
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

I tell folks to pick a phrase they can remember for long periods of time and use that regardless of the question. "my first pet" = "the refrigerator is walking" or some such thing.

Re: Jb’s story about how he nearly lost his Twitter handle

#89

The problem is that different companies have different protocols on what information they use to identify users, etc, and hackers are getting smart enough to connect various partial information to get full information on a user. Every single customer-facing company needs to have STANDARDIZED security/information protocols. This includes taking in same information, and only giving out the same information. This should…

Even with standardized security protocols, you will still have issues with undertrained/underpaid customer support agents working to "help" one very smooth talking hacker using social engineer tactics.

Re: Jb’s story about how he nearly lost his Twitter handle

#90
post #39

Earlier quoted context omitted.

If they're relying on such information for security, they aren't secure in the first place.

They don't have to be "relying" on it to use it. If you treat security like a mathematical problem [1] with no grey areas, you are going to reject almost every security measure and say "that would only give users a false sense of security." Just about all security measures can be worked around by a determined attacker. That doesn't mean you stop using them. The linked page says to hide your whois information. This is…

Also known as "defense in depth" in the security field.
Post reply on HN