Live data from Hacker News

Jb’s story about how he nearly lost his Twitter handle

d.pr

111–120 of 123 posts

Re: Jb’s story about how he nearly lost his Twitter handle

#111
post #98

Earlier quoted context omitted.

Even if customers are scatterbrained and unwilling to accept responsibility for themselves, it's still better to keep them on board and making money than trying to teach them a lesson out of principle that probably won't even stick. How well any policies are actually thought through is another matter.

Yes, because users would hate so much to be told explicitly that all they need to remember is a password. They much rather have 20 different pieces of information, some combinations of which if they share, people can take over their accounts on various services. The problem is not so much that the systems suck, the problem is there's no way for people like me to take on the responsibility and "risk" of just having a…

> Just a traditional password reset email will do

Well yes, I would much prefer that to sending in a picture of my drivers license, only logging in from one IP address, etc. This only really happens with financial sites.

For normal sites, before there were captchas, they required email to sign up, in order to deter spam. Then when they got captchas they still required both, probably because they were thinking "oh yes 2 is better than 1", even though email verification does not deter spam one bit these days. On the other hand, in more recent times you now have all these sites requiring email for recovery. You can see where the dogma came about.

I myself would absolutely never want email recovery, simply because it links the accounts together unless I make a separate email for each, wastes my time (I never lose my passwords, and they are unique for every account), and now the email provider has access to my account.

If this isn't bad enough, facebook, google, and pretty much every mainstream email provider now require a cell phone to sign up, and sends a verification code to your cell (this may be because I use tor).

It only seems to be going downhill. There's no reason not to be infuriated.

On the upside, South Korea recently abolished its law that users should use their id online:

http://online.wsj.com/news/articles/SB1000087239639044408290...

... but it's replaced with SMS:

https://en.wikipedia.org/wiki/Resident_registration_number#O...

Re: Jb’s story about how he nearly lost his Twitter handle

#112
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

I agree that security questions are 100% a joke, in that they're completely useless and potentially represent an attack vector.

Unfortunately some services have the annoying habit of randomly providing multiple choice for these (ex. TradeKing). So my qgwpagprgqrgwasr2q really sticks out as an odd answer for my first car, making it even more guessable than the real answer.

There really needs to be a way to completely opt out of these systems for competent consumers. I'd never need a password reset, so they shouldn't allow it.

Re: Jb’s story about how he nearly lost his Twitter handle

#113
post #44
post #6

I think a lot of it comes down to this: "4. Some of the biggest companies in the world have security that is only as good as a minimum-wage phone support worker who has the power to reset your account. And they have valid business reasons for giving them this power."

It could be greatly mitigated by automating that power more. E.g., "No problem, I can reset your password! The system will automatically contact your registered phone number and email address -- if you confirm both, it resets now, and if you can't, it will send the reset to your new email 3 days from now."

Or, if requested, just never allow password resets. Period.

Re: Jb’s story about how he nearly lost his Twitter handle

#114
post #87
post #13

another bad habit are those "security questions". For me, the only proper way to deal with this is to have your mother maiden or pet name be cy4nEp7UtNsz and save that (along with the question title) in your (properly backed up!) password safe.

I like how Yahoo suddenly decided to make their "security questions" a secondary password. I have no idea what I answered over a decade ago, but I can no longer log into my account despite them acknowledging my password to be correct. Where's the "reset security question" option...

Judging by the recent articles, you should at least be able to call them and get access to your (or probably someone else's) account.

Re: Jb’s story about how he nearly lost his Twitter handle

#115
post #7

It seems that now you should not only use different passwords anywhere, but also different logins and emails, different credit cards and may be even different names, addresses and phone numbers. Just to be sure.

I use different emails, for everything. I manage my own domain(s), so I have anything @mydomain.tld. I'll usually give unique email addresses that identify, to me, the organization or service that gets the address. Occasionally an address becomes the target of spam, and I just kill off that address.

Re: Jb’s story about how he nearly lost his Twitter handle

#116
post #44

Earlier quoted context omitted.

It could be greatly mitigated by automating that power more. E.g., "No problem, I can reset your password! The system will automatically contact your registered phone number and email address -- if you confirm both, it resets now, and if you can't, it will send the reset to your new email 3 days from now."

Now all an attacker has to do is wait for me to go on a cruise, or camping trip, or basically take any action which means I'm out of communication for a week or more.

Well, yeah -- I said "greatly mitigated".

I can't think of the last time I was completely cut off from both phone and email for more than 3 days. Can you? I travel around the world regularly enough (I was in Malaysia in November; I'll be in Rwanda in March), but never with breaks in connectivity lasting more than 3 days.

I don't go wandering into the wilderness for more than a day trip, admittedly... but I'm also pretty sure most other people don't do that regularly, either.

Re: Jb’s story about how he nearly lost his Twitter handle

#117
I would love for there to be some regular program of independent security auditing of major web companies focusing on social engineering attacks. It can be government-funded or privately-funded (companies would pay to be audited in order to be included in a certified registry). I'm not 100% sure how the details would work (they'd have to maintain a huge number of dummy accounts all over the place), but the value of such an effort would be tremendous.

The idea that these companies would rather cater to individuals who are careless with their accounts than uphold the sanctity of the majority of their users' identities is deeply troubling. The thought of a dispensable, minimum wage worker being all that stands between me and total calamity is terrifying.

Re: Jb’s story about how he nearly lost his Twitter handle

#118
post #94
post #82

Earlier quoted context omitted.

Please impart more wisdom in your lovely obnoxious raging nerd idealist way. It's very unusual to find in tech circles!

Ironically, HN itself so happens to do it right - it permits you to have only a user/password. Reddit is the same, so is github, stackoverflow. I've never heard of pervasive problems on either of these sites. I don't submit my email to these sites, and they work fine. Please continue to call common fucking sense idealism. Look how shit any other site besides the 4 (and others like them) I mentioned are with their fan…

Github has 2-factor authentication BTW.

Re: Jb’s story about how he nearly lost his Twitter handle

#119
post #115
post #7

It seems that now you should not only use different passwords anywhere, but also different logins and emails, different credit cards and may be even different names, addresses and phone numbers. Just to be sure.

I use different emails, for everything. I manage my own domain(s), so I have anything @mydomain.tld. I'll usually give unique email addresses that identify, to me, the organization or service that gets the address. Occasionally an address becomes the target of spam, and I just kill off that address.

That wouldn't really helped you in this case, would it? The attacker got the account reset simply by phoning the customer service and making them send a password reset link to a new email.

Also how do you manage said X number of emails? Do you log onto each one of them, or do you forward all emails to one "master email"? If so, the master email is still the single point of failure.

Re: Jb’s story about how he nearly lost his Twitter handle

#120
post #59
post #30

Earlier quoted context omitted.

Phone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.

That's not completely true. If you're in an old Ameritech area in Ohio, pick up the phone, dial '0' and when the Operator comes on, say: "OBT-125, please read number on display." You'll get the NPA-NXX-XXXX read out to you and she'll tell you to have a good day. As of three years ago, you could call any of the embarq/sprint area operators in Ohio/Kentucky and just say, "ID Me." Phone phreaking is still alive, but, it…

Can someone from the area try this and report back?
Post reply on HN