Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

91–100 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#91

The problem is that different companies have different protocols on what information they use to identify users, etc, and hackers are getting smart enough to connect various partial information to get full information on a user. Every single customer-facing company needs to have STANDARDIZED security/information protocols. This includes taking in same information, and only giving out the same information. This should…

Even with standardized security protocols, you will still have issues with undertrained/underpaid customer support agents working to "help" one very smooth talking hacker using social engineer tactics.

Social engineering is always a problem, and I think first-level support should NEVER have the ability to see any information or have the ability to make changes to accounts. This should get escalated to second level support.

But regardless, a single account may get compromised, but at least you can't feed partial data from one social engineering attempt into another company, which is what apparently is happening more and more because of impedance mismatches with what everyone uses.

Re: Jb’s story about how he nearly lost his Twitter handle

#92
post #87
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

I like how Yahoo suddenly decided to make their "security questions" a secondary password. I have no idea what I answered over a decade ago, but I can no longer log into my account despite them acknowledging my password to be correct. Where's the "reset security question" option...

Or even Gmail. Since when do they require you to guess when you opened your account and all of that information? As if I have any idea what month/year I opened my gmail account. I feel like if I ever got locked out of it or were in this situation I wouldn't know the information to get back into it.

Re: Jb’s story about how he nearly lost his Twitter handle

#93
post #39

Earlier quoted context omitted.

If they're relying on such information for security, they aren't secure in the first place.

They don't have to be "relying" on it to use it. If you treat security like a mathematical problem [1] with no grey areas, you are going to reject almost every security measure and say "that would only give users a false sense of security." Just about all security measures can be worked around by a determined attacker. That doesn't mean you stop using them. The linked page says to hide your whois information. This is…

To be picky, if you're treating it mathematically the phrase "sense of security" has no meaning.

Re: Jb’s story about how he nearly lost his Twitter handle

#94
post #82
post #56

Earlier quoted context omitted.

Oh wait, I forgot this is HN, where conforming to retarded dogma is the only way to be cool.

Please impart more wisdom in your lovely obnoxious raging nerd idealist way. It's very unusual to find in tech circles!

Ironically, HN itself so happens to do it right - it permits you to have only a user/password. Reddit is the same, so is github, stackoverflow. I've never heard of pervasive problems on either of these sites. I don't submit my email to these sites, and they work fine.

Please continue to call common fucking sense idealism. Look how shit any other site besides the 4 (and others like them) I mentioned are with their fancy policies. How can anyone not rage when such stupidity is forced upon us?

Re: Jb’s story about how he nearly lost his Twitter handle

#96
post #38

Jesus fucking christ. Stop making websites accept anything other than a username+password/token for authentication, and this kind of retarded shit would never happen. It's somehow still the status quo to make backdoors to recover your account incase you lock yourself out, which is why things like this happen all the time. You get what you deserve.

BTW, this comment was meant to be in response to the other thread "How I Lost My $50,000 Twitter Username (medium.com)"

https://news.ycombinator.com/item?id=7141532

But they're both pretty much the same problem. Service has complex/secret authentication policy, so users have no chance to be secure.

Re: Jb’s story about how he nearly lost his Twitter handle

#97
post #87
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

I like how Yahoo suddenly decided to make their "security questions" a secondary password. I have no idea what I answered over a decade ago, but I can no longer log into my account despite them acknowledging my password to be correct. Where's the "reset security question" option...

I actually ran into this the other day. The account I had used from 8th grade to about 11th is now probably gone forever.

Re: Jb’s story about how he nearly lost his Twitter handle

#98
post #94
post #82

Earlier quoted context omitted.

Please impart more wisdom in your lovely obnoxious raging nerd idealist way. It's very unusual to find in tech circles!

Ironically, HN itself so happens to do it right - it permits you to have only a user/password. Reddit is the same, so is github, stackoverflow. I've never heard of pervasive problems on either of these sites. I don't submit my email to these sites, and they work fine. Please continue to call common fucking sense idealism. Look how shit any other site besides the 4 (and others like them) I mentioned are with their fan…

Even if customers are scatterbrained and unwilling to accept responsibility for themselves, it's still better to keep them on board and making money than trying to teach them a lesson out of principle that probably won't even stick.

How well any policies are actually thought through is another matter.

Re: Jb’s story about how he nearly lost his Twitter handle

#100

One thing I've found handy is just to have little or no bio information on your accounts. If you absolutely must have bio info on your account, make all the information different from account to account. This way, if a hacker gets your LinkedIn profile, the information there is different than your Facebook info, which is different than your Twitter info, which is different from your. . Imagine a hacker with a handful…

Have you been the target of hacking attempts? This sounds the opposite of handy, so I'd be interested to know how well it actually works. Not sure how well it would pay but I'd be interested in a service that attempts to steal your identity in this way, and then tells you what you can do to plug the vulnerabilities.

I have not been targeted, I just tend to think like a hacker so I take a lot of precautions to protect my identity.
Post reply on HN