Live data from Hacker News

Finding vulnerable Twitter accounts with expired domains

zainamro.com

111–120 of 128 posts

Re: Finding vulnerable Twitter accounts with expired domains

#111
post #29

Earlier quoted context omitted.

Without sharing examples, this is effectively a non-answer. Thanks for the comment.

In Sweden, BankID covers well over 90% of the population between ages 20 and 60 with a unique electronic ID. (Including 98% of those between 20 and 40.) It supports identifying yourself with a credit card and pin using a card reader given to you by your bank or alternatively (and more commonly) a pin combined with a smartphone/computer that you have identified as being yours.

And as a result we have a lot of bank accounts hacked over phone because people don't know how to use it. Or more importantly how NOT to use it. All it takes is a phonecall to someone, tell them someone is trying to hack into their bank account and they need to hurry and ID themselves because the thief is running off with their pension. The police get these kinds of cases every day.

I love BankID but I have been using it since the start and know the pitfalls to watch out for. Most people does not know the problems though.

Re: Finding vulnerable Twitter accounts with expired domains

#112
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

Indeed. What if you are a super responsible person, but there is unrest in a Country you are visiting or live in, through no fault of your own and you are unable to pay a renewal. Or you fall sick and go to the hospital.

Re: Finding vulnerable Twitter accounts with expired domains

#113
post #23

What would be a universal solution to this problem? The only thing I can really think of is platforms not allowing custom domains for connected email accounts, but that seems sub-optimal.

Instead of blocking custom domain email addresses outright, the site could require a secondary recovery email address from an approved provider when an email with a custom domain is used to create the account. Then any security interaction like password reset, or 2fa would go to the primary address and would send an alert to the secondary email address about the nature of the communication. There could be a link in t…

> the site could require a secondary recovery email address from an approved provider

No. I have a domain precisely because of avoiding a monopoly, duoplily, oligopoly on my email. Any service that required this would have me walk. The footsteps of a single zhte415 may not be loud, but I feel, especially in tech, I would not be alone.

Re: Finding vulnerable Twitter accounts with expired domains

#114
post #14

Earlier quoted context omitted.

I don’t think you having to either A) remember what email you used or B) creating a new account is a big ask when the alternative is leaking your account presence on a given system. Not everyone wants other people to be able to essentially query a given app for an email account.

The vast majority of people don't use the same e-mail address for their entire lives.

You're right. An example use case.

Monitor having issues. Google solution. Land on a forum, but to see the full post / solution it requires email registration. I register with a junk yahoo type email address. Complete the long form, solve all the traffic lights, etc. Then get the solution, make a few posts and probably forget about it.

Monitor having problem again after 2 years same forum but it says my very unique username is taken. Now, I vaguely remember creating an account but don't remember what email I used. I try to reset my password but dang, each time it says "If that email was in our db you'll get it". If I get a hint I used yahoo maybe I can resume and hopefully use my old account and some post count than starting a 1 day old account with 0 post.

Re: Finding vulnerable Twitter accounts with expired domains

#115
post #84

Earlier quoted context omitted.

I guess the approaches taken with U2F tokens here (and FIDO2) makes sense - have more than one token enrolled, and allow either to be used. It's not perfect and there are usability issues around this, but they're mostly solvable. Needing both keys around to enrol into each service can be an issue, but this could be addressed by letting a user enrol other public keys as a delegate, and present a signed delegation toke…

Yeah, I just can't see getting my 75 year old dad to be able to use a system like that.

Agreed, although most of this will end up wrapped up into the token and system itself, I suspect.

U2F is pretty much a "key" (some even visually looking like keys) that are used pretty much like a physical key - put the key into the keyhole (USB port), and press the flashing light. Done.

That level of UX is what we all need to build towards!

Re: Finding vulnerable Twitter accounts with expired domains

#116

Earlier quoted context omitted.

The vast majority of people don't use the same e-mail address for their entire lives.

You're right. An example use case. Monitor having issues. Google solution. Land on a forum, but to see the full post / solution it requires email registration. I register with a junk yahoo type email address. Complete the long form, solve all the traffic lights, etc. Then get the solution, make a few posts and probably forget about it. Monitor having problem again after 2 years same forum but it says my very unique u…

So your idea is to always gives malicious actors additional information for account take overs so you can use an account with a non zero post count (not just non-zero, but only 1 or 2 as you insinuated)? Do you not see how naive that is?

Re: Finding vulnerable Twitter accounts with expired domains

#117
post #101
post #70

Earlier quoted context omitted.

But that doesn’t matter! I hate this argument because it misses the point of biometric authentication as “something you are.” There’s no such thing as compromise or revocation. It’s a piece of public information that can’t be stolen or used by anyone other than yourself. The world can have high def scans of my fingerprint for all it matters, they can’t produce a living human finger with the same print. And if you can…

> It’s a piece of public information that can’t be stolen or used by anyone other than yourself. The point here is that this is completely wrong. Biometrics can be stolen and they're unreplaceable. There's no device in the world that can be sure it's reading a fingerprint from a living human. Drop a quick query into Google, you'll find dozens of methods that fool Apple's TouchID and that's probably one of the more ro…

If you take the position that nobody, even a human sitting at a desk taking prints by hand, can verify that they’re reading from a living human then biometrics and every “something you are” auth is totally useless for all applications.

If you think of biometric auth as “the scan of your eye/hand/whatever is just a password” then I can’t help you and of course that system can be compromised. “Upload a PDF of your fingerprint" is the silliest auth system of all time.

Re: Finding vulnerable Twitter accounts with expired domains

#118
post #74
post #70

Earlier quoted context omitted.

But that doesn’t matter! I hate this argument because it misses the point of biometric authentication as “something you are.” There’s no such thing as compromise or revocation. It’s a piece of public information that can’t be stolen or used by anyone other than yourself. The world can have high def scans of my fingerprint for all it matters, they can’t produce a living human finger with the same print. And if you can…

> Biometrics is not transmitting a picture of a fingerprint, it’s presenting your hand. What would this "hand data" look like? A 3D model of a hand MRI or X-Ray? Based on my understanding, in any form of biometric authentication, some amount of static data (i.e. the biometric database is not receiving a secure, updating feed of the state of your hand/body) is stored on the server and compared with the data transmitte…

> If someone can compromise your "full hand scanner" or compromise the biometric database (which will inevitably happen), then you are compromised for life, since you cannot change your hand.

Suppose this happens. The world now knows all of your fingerprints. And at some point in the future you walk up to the desk of a datacenter where there's a security guard who phyiscally takes your hand, inspects it, and places it on the scanner. Can someone other than you pass this check?

Biometrics are a hard, mostly unsolved the problem, because the hard part is replacing the human security guard who verifies that you're scanning a real person's hand. For not super security sensitive applications TouchID, FaceID, and friends are good enough because most people aren't in Face Off or Mission Impossible.

Re: Finding vulnerable Twitter accounts with expired domains

#119
post #117
post #101

Earlier quoted context omitted.

> It’s a piece of public information that can’t be stolen or used by anyone other than yourself. The point here is that this is completely wrong. Biometrics can be stolen and they're unreplaceable. There's no device in the world that can be sure it's reading a fingerprint from a living human. Drop a quick query into Google, you'll find dozens of methods that fool Apple's TouchID and that's probably one of the more ro…

If you take the position that nobody, even a human sitting at a desk taking prints by hand, can verify that they’re reading from a living human then biometrics and every “something you are” auth is totally useless for all applications. If you think of biometric auth as “the scan of your eye/hand/whatever is just a password” then I can’t help you and of course that system can be compromised. “Upload a PDF of your fing…

> “the scan of your eye/hand/whatever is just a password” then I can’t help you and of course that system can be compromised.

Unless you have a human to sit there validate that they're reading from an actual human, isn't this essentially what biometric auth is? Am I missing something here? No reasonably sized machine can certainly do the needed verification with the limited information they have.

Not to mention - if it were to be heavily relied upon for security for a very high value target, say one of those bitcoin vaults with hundreds of millions of dollars locked away, you can certainly envision a world where you could get grafted silicone fingertips installed by a plastic surgeon that would likely fool humans based on the exact sort of data leak we discussed.

Re: Finding vulnerable Twitter accounts with expired domains

#120
post #119
post #117

Earlier quoted context omitted.

If you take the position that nobody, even a human sitting at a desk taking prints by hand, can verify that they’re reading from a living human then biometrics and every “something you are” auth is totally useless for all applications. If you think of biometric auth as “the scan of your eye/hand/whatever is just a password” then I can’t help you and of course that system can be compromised. “Upload a PDF of your fing…

> “the scan of your eye/hand/whatever is just a password” then I can’t help you and of course that system can be compromised. Unless you have a human to sit there validate that they're reading from an actual human, isn't this essentially what biometric auth is? Am I missing something here? No reasonably sized machine can certainly do the needed verification with the limited information they have. Not to mention - if…

I totally agree with you, this is why biometrics are this weird open for machines, but solved for humans problems. If you don't trust the scanner then it's useless. Depending on your threat model you can do really fancy stuff like retina scans that detect blood flow and temperature or TouchID for less-sensitive stuff like a screen lock.

> You can certainly envision a world where you could get grafted silicone fingertips.

If you built a system that's so secure that this is the lengths you have to go to beat it then you would be an overnight billionaire if you brought it to market. Like at this point you've achieved human-level verification. Assuming it was small enough to go in phones it would be revolutionary!

Post reply on HN