Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

121–130 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#121
post #93

Earlier quoted context omitted.

I never quite got this "mother's maiden name" thing. Isn't your mother's maiden name... your mother's current name, minus the extra surname she got when she married? Why is this treated as a hard-to-discover information?

In the US and other countries it's common for a wife to take her husband's last name. Changes from "Jane Doe" to "Jane Smith"

Yeah, but often (usually?) the woman's maiden name replaces her middle name. E.g. Jane Elizabeth Doe -> Jane Doe Smith. I'm pretty sure my mom's maiden name is printed on her driver's license, paper checks, etc.

Re: Post a boarding pass on Facebook, get your account stolen

#122
post #40

Earlier quoted context omitted.

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

But the attacker kind of has to know the answer is gibberish from the bat, otherwise they'd either guess or pretend to not remember a real answer, which is noticeably different from saying something like "oh, that's 30 random characters but I don't have the note with me right now".

But we already know @sersi just mashes the keyboard for those questions :)

Re: Post a boarding pass on Facebook, get your account stolen

#123
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

My bank's terms of service bans recording passwords - ie managers.

Re: Post a boarding pass on Facebook, get your account stolen

#124
post #78

Earlier quoted context omitted.

"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.

The first time (years ago...) I had to enter my birth date on a website that asked it to me for no valid reason, there was a default value. It's now my birthdate on every others !

January 1st 1970 is sometimes known as "The Internet's birthday" for this reason..

Re: Post a boarding pass on Facebook, get your account stolen

#125
post #123
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

My bank's terms of service bans recording passwords - ie managers.

How are they supposed to know you use one?

Re: Post a boarding pass on Facebook, get your account stolen

#126
post #105

Earlier quoted context omitted.

It's not about what you say, it's about what an attacker can get away with saying. And they can almost certainly get away with "I just mash the keyboard."

Ah, I see what you mean. Perhaps instead of grabbing a handful of characters from /dev/urandom, you generate a passphrase (a few random dictionary words)?

Sounds like a "correct battery horse staple" would fit the bill

Re: Post a boarding pass on Facebook, get your account stolen

#127
I don't know if it's the case elsewhere but starting 2019 all invoice payments in Switzerland will use mandatory QR codes. https://www.paymentstandards.ch/en/home/softwarepartner/qr-b... That promises to be challenging too in terms of publication of sensitive data.

Re: Post a boarding pass on Facebook, get your account stolen

#128
post #80

post a boarding pass on facebook, get your account stolen? there's an alternate title for this one. post about commandeering accounts on your blog, get the CFAA thrown at you and go to jail. this is anything but responsible.

Presumably he's not located in the US.

Re: Post a boarding pass on Facebook, get your account stolen

#129
post #121

Earlier quoted context omitted.

In the US and other countries it's common for a wife to take her husband's last name. Changes from "Jane Doe" to "Jane Smith"

Yeah, but often (usually?) the woman's maiden name replaces her middle name. E.g. Jane Elizabeth Doe -> Jane Doe Smith. I'm pretty sure my mom's maiden name is printed on her driver's license, paper checks, etc.

I know very few women that have done that TBH.

Re: Post a boarding pass on Facebook, get your account stolen

#130
post #81

Earlier quoted context omitted.

Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone

Not just easier, but actually more safe. The person on the phone isn't usually aware about your security "paranoia" and is being evaluated on how much customers he/she has been able to help. As such most helpdesk employees will accept the answer "Oh I forgot, I do remember I put some random characters in there"... and your random password end up not helping you after all.

As noted in another comment, the attack on this of "oh I forgot, it's random characters" requires the attacker to know you do this. So if you do this, don't go disclosing it on public websites.
Post reply on HN