Earlier quoted context omitted.
Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone
I believe the general recommendation I saw was to type something in lines of "never accept this answer - it's probably someone trying to impersonate me | 2DXSDGREDV@#!" (although it's probably hard to do so if the maximum acceptable length is too short)
Post a boarding pass on Facebook, get your account stolen
111–120 of 313 posts
Re: Post a boarding pass on Facebook, get your account stolen
#112Earlier quoted context omitted.
"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.
Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone
Re: Post a boarding pass on Facebook, get your account stolen
#113Earlier quoted context omitted.
Gotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.
Isn't embedding QR codes the reason they were created in the first place? It's an optical data format designed to be easy for computers to read. You're basically evaluating the cryptographic merits of CSV.
I am not. I am weighing features vs unintended harm. Yes, the airlines shouldn't be including this data in the barcodes. It is improper to expose end users to this liability. And simply telling them not to expose them isn't a solution.
But if FB can detect harmful barcodes in an image, by all means they should remove the photo.
This is no different than Github scanning for AWS creds or MongoDB passwords in repos.
Re: Post a boarding pass on Facebook, get your account stolen
#114Earlier quoted context omitted.
Gotta weaken security for everyone because you want your embedded QR codes? Most likely the only person on FB who has done this.
The issue here is the airlines, not Facebook...
Facebook already scans the image, probably even for QR codes, they could prevent users from harming themselves. And airlines shouldn't expose this info in the first place.
Re: Post a boarding pass on Facebook, get your account stolen
#115And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…
> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..
Re: Post a boarding pass on Facebook, get your account stolen
#116And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…
> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..
Re: Post a boarding pass on Facebook, get your account stolen
#117Earlier quoted context omitted.
Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone
I don't even try to make it sound legitimate. e.g. How many sisters do you have? Anyone guessing will be trying a number between 0 and 5. I use a semi-random word, colour or car I associate with my sister(s), eg. Audi. When asked for a number no one guessing will respond with a car make.
You don't have to answer the challenge with a 100% truthful, legitimate, accurate response, because the point is to NOT provide an answer that could be guessed by framing the response in truth, or even reality. So long as you've picked one that matches with what you've preseeded, use a random word/phrase as your response.
q: What is the name of your favorite teacher? a: bumble bees in the desert
Re: Post a boarding pass on Facebook, get your account stolen
#118Earlier quoted context omitted.
Doesn't the QR standard allow lowercase via hex and have a miniature version? I know it has error correction, but I'm not sure if it is tunable. I know it can embed kanji, so it seems odd that lowercase would be much of a problem? Thanks! I am pretty grateful I'm not tasked with implementing these.
It's not that lowercase is a problem , it's that aztec is more efficient at it. Note that GP is incorrect that you need lowercase to express URLs and qrcode has an "alphanumeric" mode (based around uppercases which works fine), but even then qrcode's alphanumeric mode is slightly less efficient as it needs 5.5 bits per character versus 5 for Aztec. Kanji has its own qrcode encoding mode (the qrcode encoding modes are…
What I do like about HN is the comments. Someone here usually knows what they are talking about and can explain it well.
Thanks!
Re: Post a boarding pass on Facebook, get your account stolen
#119Earlier quoted context omitted.
Doesn't the QR standard allow lowercase via hex and have a miniature version? I know it has error correction, but I'm not sure if it is tunable. I know it can embed kanji, so it seems odd that lowercase would be much of a problem? Thanks! I am pretty grateful I'm not tasked with implementing these.
QR codes have variable-level error-correction, from 7-30%. https://en.wikipedia.org/wiki/QR_code#Error_correction
I'd ask why they didn't just improve QR codes, instead of making yet another format, but I'm not sure I want to know the answer(s).
Re: Post a boarding pass on Facebook, get your account stolen
#120Earlier quoted context omitted.
I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…
If you booked the flights together, and paid together, it's probably pretty likely that you are travelling together. If the flights were booked together, I don't think this is out of line.