Live data from Hacker News

Congressman's phone password is 111111

gfycat.com

121–130 of 206 posts

Re: Congressman's phone password is 111111

#121
post #94
post #3

That is a iPhone X like device, which only has Face ID or a PIN. A PIN is more secure than a fingerprint and Face ID. But at least use a combination of either one with a PIN to make it more secure. Since the device was already on and it directly showed the PIN screen, Face ID is disabled and instead he chooses to only use a very very weak PIN. Oh dear.

It has a notch, but I am unsure if it is an iPhone?

It opened up to iMessages (blue and white conversations), it's an iPhone

Re: Congressman's phone password is 111111

#122

I always thought that Android's 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.

Well, if you had a flir camera looking over your shoulder the tracing effect (caused by localised heating of the screen) would still be there. I actually heard it is a legit method to defeat pin entry systems. If you can get to the terminal soon enough it was used, relevant keys will be a little hotter than the other. This will be visible with flir. Then all you have to do is figure out the order of digits.

Re: Congressman's phone password is 111111

#123
post #10

I tell this story a lot. But I think in the time of smartphones and such it also represents the only real secure site I thought was truly secure from what I knew of it. This was before smartphones were common, but I think it was ahead of its time in that way. I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they…

Why would you be willing to work in such conditions? If my employer demanded to send me to such a facility I would happily tell them to shove it and look for another job.

Re: Congressman's phone password is 111111

#124
post #10

I tell this story a lot. But I think in the time of smartphones and such it also represents the only real secure site I thought was truly secure from what I knew of it. This was before smartphones were common, but I think it was ahead of its time in that way. I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they…

I'm hoping they've implemented some form of localized EMP that you have to pass through now to leave, because large storage is so incredibly small now that it would be impossible to discern it from articles of clothing. The "hard" part is really just getting the data off the computer in the first place, which is probably why they don't allow bringing in technology anymore. I wonder how much of a micro computer could…

What if you stick the flash drive up really far up your bum? Wouldn't the saltwater in your body form a Faraday cage around it?

Re: Congressman's phone password is 111111

#125

I always thought that Android's 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.

You can often see these very obvious smudges on the screen

Re: Congressman's phone password is 111111

#126

If I were giving a security recommendation to famous people and congresspeople I would recommend using a password like this. You might think it’s incredibly insecure, but imagine this GIF contained that 6 digit number that the congressman uses for all of his accounts. Suddenly, a ton of other services and passwords are vulnerable to an attacker. In reality a lot of iPhones now require authentication at the app level…

> In reality a lot of iPhones now require authentication at the app level for apps that have sensitive data.

I'm fairly certain that knowing my passcode would provide access to my email, which can then be used to acquire access to plenty of critical services.

Re: Congressman's phone password is 111111

#127

I always thought that Android's 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.

I prefer to use the draw password but honestly if you look at the finger smudges on my phone, you could probably still guess my pattern.

Yep, pretty easy to do - especially if your pattern is recognizable or doesn't cross over itself.

"Oh hey, cool, a Σ!"

Re: Congressman's phone password is 111111

#128

Earlier quoted context omitted.

The "localised EMP" you mention could simply be a low power microwave oven of same type we have in our kitchens you have to walk through. Waves of that frequency would not harm a person if they were fairly low power, but it would mess up every bit of non-metal-shielded electronics. If you want to destroy a piece of electronics quickly put it in a microwave oven and hit start (also don't expect to eat from that oven l…

Remember to switch it off if you invite Dick Cheney in for a visit, though. Frying his pacemaker would be a bit of a PR hit.

You made it weird by singling out Cheney, but impact on medical devices is an important consideration for any such scheme.

Re: Congressman's phone password is 111111

#129

The problem isn't the password or the camera that captured it. The problem is that the phone required a password in that scenario-- same user, phone never left his vicinity, probably not a long interval between uses. Being more selective about when to require a master password is a better protection model IMHO.

Soli on the new Pixel 4 could easily allow that.

Re: Congressman's phone password is 111111

#130
post #78

And yesterday over a dozen members of Congress barged into one of the Congressional versions of this site without authorization and while recording video, audio, and taking photos on their personal smartphones. Here is a Twitter thread about why that is such a problem: https://twitter.com/MiekeEoyang/status/1187032800572125191

[flagged]

>And sometimes such actions are necessary

Sure, maybe sometimes they're necessary, but this isn't one of them. Leaving your phone behind isn't difficult. They may have a legitimate gripe, and this was a theatrical way of shining light on it, but there was nothing inherent to their stunt that prevented its execution while keeping a secure site secure.

Post reply on HN