Live data from Hacker News

Hackers went undetected in Citrix’s internal network for six months

techcrunch.com

121–122 of 122 posts

Re: Hackers went undetected in Citrix’s internal network for six months

#121
post #120
post #119

Earlier quoted context omitted.

>> Basically, the ability for someone to log into my account by brute forcing or obtaining my credentials > you ensure that people cannot log in with credentials, even if they have them. Except that you left out the second part of that sentence: >> or being able to bypass the log on process by using the conventional second auth factor against me (by doing the same thing to my email account and/or my cell phone provid…

When technical security items have been pointed out repeatedly to you, you keep answering without addressing those security points. A valid security design should understand the threats that are being guarded against instead of simply throwing out a favored design.

It seems that you're fixated on the terms used in the discussion rather than the substance of the discussion itself. I already provided an example where someone fell victim to the SIM swap scam because they had their cell phone number on file with their bank.

But rather than addressing the issues where a 3rd party serving as a second factor/step can be compromised without the account holder realizing it in time or the fact that U2F doesn't support other protocols besides HTTPS, you keep going on and on about "security points" which appear to be nebulous in the context of this discussion and also cherry-pick my responses only to go off on a largly irrelevant tangent.

This discussion could have been useful, but, unfortunately, it didn't turn out that way.

Re: Hackers went undetected in Citrix’s internal network for six months

#122
post #121
post #120

Earlier quoted context omitted.

When technical security items have been pointed out repeatedly to you, you keep answering without addressing those security points. A valid security design should understand the threats that are being guarded against instead of simply throwing out a favored design.

It seems that you're fixated on the terms used in the discussion rather than the substance of the discussion itself. I already provided an example where someone fell victim to the SIM swap scam because they had their cell phone number on file with their bank. But rather than addressing the issues where a 3rd party serving as a second factor/step can be compromised without the account holder realizing it in time or th…

You misunderstand. I am not fixating on the terms, but the concept underlying the factors of identification. The point, which I stated in my first comment is that you are not taking into consideration the difference between 1.5 factor auth and 2 factor auth. Then, you are further compounding the security error, but discussing other issues instead of directly addressing that your solution doesn't address the threat model. That is why I asked what threats you are guarding against. There is a large body of knowledge here that may be worth your study, cf cia.

Yes, there is a fixation on security, since authentication is a security function that is often gotten wrong when people don't know the threat model and rush through a solution. This has been pointed out to you by several people more than once in this very thread.

Post reply on HN