Live data from Hacker News

Urgent security warning that may affect all internet users

community.namecheap.com

81–90 of 120 posts

Re: Urgent security warning that may affect all internet users

#81
post #51

The question for us, as technologists, is what are we doing about this? 2FA is nice, but not the end all, be all. OAuth has largely failed to gain any reasonable traction. Using Facebook login means Facebook gets to track me as I move around the web. Our users reuse passwords, primarily due to the proliferation of dozens or often hundreds of online accounts that a single individual has. We can't expect people to use…

Just throwing this out there but when signing up for sites while using Safari, Apple gives me the option of using a (Apple generated) random password that is stored to my keychain and synced to my iCloud account. This means both of my MacBooks, my iPhone, and my iPad all have access to these sites with no effort on my part (I never could remember my passwords) while also being random and secure(-ish?).

All that is needed is a service (Microsoft, Google, Apple, Facebook) that you trust as your password manager and is integrated either with the sites you browse or the browser you use.

Having read Apple's iOS security document (http://www.apple.com/ipad/business/docs/iOS_Security_Feb14.p...) I have just the right combination of convenience, ease of use, and feeling secure with their services to use keychain for most of my password needs.

Re: Urgent security warning that may affect all internet users

#82
post #14
post #13

Earlier quoted context omitted.

To save time for those hunting for this on Namecheap: 1. Log in 2. Click "Menu" (in the top right portion of the page) 3. Expand the "My Account" submenu (if it didn't already automatically expand when the menu appeared) 4. Click "Manage Profile" (5th from the bottom of the "My Account" submenu) 5. On the next page that appears, look for "Two Factor Authentication" on the left side under "Personal Settings"

Thanks! Also, a direct link if you're already logged in: https://www.namecheap.com/myaccount/TwoFA/TwoFAProfileManage...

My phone often has no service, which would make 2FA with you a roadblock. Please consider using Google Authenticator for generating the code, instead of sending a text or voice call.

Re: Urgent security warning that may affect all internet users

#83

Earlier quoted context omitted.

Why not just use: https://lastpass.com/ https://agilebits.com/onepassword http://keepass.info/

Isn't there greater risk in using these than my method? My logic: If one of these solutions e.g. LastPass is compromised then I am compromised across all sites. They may even bypass 2 factor authentication that goes via my email/messaging. Whereas using my method if one website gets hacked then I only give access to a segment. If it is worst case and a financial site is compromised they still don't have the password…

KeePass is just an encrypted database stored on your machine. If it's compromised, your machine is compromised, so you're screwed either way. Meanwhile, if any of many online services you use are compromised (and some inevitably will be), you have minimised the cost of that.

Re: Urgent security warning that may affect all internet users

#84
post #51

The question for us, as technologists, is what are we doing about this? 2FA is nice, but not the end all, be all. OAuth has largely failed to gain any reasonable traction. Using Facebook login means Facebook gets to track me as I move around the web. Our users reuse passwords, primarily due to the proliferation of dozens or often hundreds of online accounts that a single individual has. We can't expect people to use…

[deleted]

Re: Urgent security warning that may affect all internet users

#85
post #12

Hey all, Teddy from Namecheap here. Happy to answer any questions here or at ted@namecheap.com. As always, we advise turning on 2-factor authentication on your account.

Why did you have to bring up the specific "CyberVor" incident that has been called out as bullshit by several people in the security industry?

Re: Urgent security warning that may affect all internet users

#86
post #66
post #51

The question for us, as technologists, is what are we doing about this? 2FA is nice, but not the end all, be all. OAuth has largely failed to gain any reasonable traction. Using Facebook login means Facebook gets to track me as I move around the web. Our users reuse passwords, primarily due to the proliferation of dozens or often hundreds of online accounts that a single individual has. We can't expect people to use…

All the security measures usually presented (including here) are completely unrealistic - no one can use different, complex passwords on every site we log into, and then change them every month! The only way to do this would be to use a password manager in an Saas mode... and if it gets cracked then you're completely doomed and lose all access to all services. People probably assume that the time saved by not caring…

I do exactly that, using keepassX. Single use, complex passwords that I change every two months, stored in a shared encrypted database.

What exactly is hard about it?

Re: Urgent security warning that may affect all internet users

#87
post #86
post #66

Earlier quoted context omitted.

All the security measures usually presented (including here) are completely unrealistic - no one can use different, complex passwords on every site we log into, and then change them every month! The only way to do this would be to use a password manager in an Saas mode... and if it gets cracked then you're completely doomed and lose all access to all services. People probably assume that the time saved by not caring…

I do exactly that, using keepassX. Single use, complex passwords that I change every two months, stored in a shared encrypted database. What exactly is hard about it?

keepassX seems to be a local application: how do you use it on mobile, or when you're not at home?

Also: if the database gets corrupted, you lose access to all services; if you have backups then it's a little less safe; if the main password for the database is strong you may forget it (or need to write it down somewhere outside the system); if it's not strong it's not safe.

Re: Urgent security warning that may affect all internet users

#88
post #81
post #51

The question for us, as technologists, is what are we doing about this? 2FA is nice, but not the end all, be all. OAuth has largely failed to gain any reasonable traction. Using Facebook login means Facebook gets to track me as I move around the web. Our users reuse passwords, primarily due to the proliferation of dozens or often hundreds of online accounts that a single individual has. We can't expect people to use…

Just throwing this out there but when signing up for sites while using Safari, Apple gives me the option of using a (Apple generated) random password that is stored to my keychain and synced to my iCloud account. This means both of my MacBooks, my iPhone, and my iPad all have access to these sites with no effort on my part (I never could remember my passwords) while also being random and secure(-ish?). All that is ne…

Awkward time to bring up iCloud as a potential SPOF for users' security. Apart from technical flaws in the service (and any cloud service is likely to have one eventually), cryptographer Matt Green (on his twitter feed) has pointed out that Apple chose some poor defaults, particularly the use of peoples' phone password as default for cloud storage. Quoth Matt, "Of course people pick terrible iCloud passwords. You can't enter a good password 50x per week on a mobile device. You'll go carpal." (In subsequent tweets, he acknowledges that password caching would help with this, but says he had to turn it off after his kids ran up a $200 bill.)

Of course, it's not clear that password brute-forcing was what led to the recent leaks of celebrity nude selfies, and not even complely clear that they came from iCloud (though a lot of clues point that way). But regardless, they do illustrate the risks of relying on cloud storage generally, regardless of who provides it.

Re: Urgent security warning that may affect all internet users

#89
post #65

Earlier quoted context omitted.

two factor authentication via SMS is the biggest waste of time. It's not true two factor authentication as you need to depend on the network and protocol between namecheap and my phone. Not to mention the code is probably not originating from a namecheap server but from a third party service. TOTP is a standard, it's great, there are open source implementations, and it's easy to integrate. Google even has that pam mo…

> It's not true two factor authentication as you need to depend on the network and protocol between namecheap and my phone. That's rubbish. 2FA means 'something you know and something that you have'. What you know is your account credentials, what you have is your phone.

I don't think you understood my comment. SMS is not something "you have". You have your phone, the SMS is sent (presumably from namecheap, or from a third party service) through the network and arrives at your phone.

This means at any point between the sender and your phone anyone who has access can know what your "two factor" code is.

If you use true TOTP, i.e. Google Authenticator, then the code is generated via a secret key that lives on your phone, and nothing ever leaves your phone besides printing to screen and showing it to you when you need to log in.

Therefore, SMS "two factor" is not only costly and annoying, but ineffective.

Can I get my upvote back?

Re: Urgent security warning that may affect all internet users

#90

I've seen a huge uptick in spam email the last few days, and although I have no indication that I've been hacked, I feel as though I should probably fear for the worst and aggressively change all my passwords from their current kindergarten security levels. Is there a widely accessible, secure, multi platform, free/libre password manager that is recommendable as easy to use? I reuse passwords because its easy to reme…

Keepass is what you want.
Post reply on HN