Live data from Hacker News

Finding vulnerable Twitter accounts with expired domains

zainamro.com

121–128 of 128 posts

Re: Finding vulnerable Twitter accounts with expired domains

#121
post #107

Earlier quoted context omitted.

Well, lost or stolen hopefully wouldn't happen if it's embedded in my hand—that's the point of embedding it in my hand! To protect against damage—which is a very real possibility, of course—I'd put identical chips in each hand, and if one fails or gets damaged, then you'd have to rotate keys by replacing both chips. And you could have a third identical chip/key (or a different private key on another device in a safe…

I prefer losing the keys to my email than to lose my hand because someone wants to empty my bank account.

I'm not really conerned about that scenario, to be honest.

Re: Finding vulnerable Twitter accounts with expired domains

#122
post #101
post #70

Earlier quoted context omitted.

But that doesn’t matter! I hate this argument because it misses the point of biometric authentication as “something you are.” There’s no such thing as compromise or revocation. It’s a piece of public information that can’t be stolen or used by anyone other than yourself. The world can have high def scans of my fingerprint for all it matters, they can’t produce a living human finger with the same print. And if you can…

> It’s a piece of public information that can’t be stolen or used by anyone other than yourself. The point here is that this is completely wrong. Biometrics can be stolen and they're unreplaceable. There's no device in the world that can be sure it's reading a fingerprint from a living human. Drop a quick query into Google, you'll find dozens of methods that fool Apple's TouchID and that's probably one of the more ro…

Encryption isn't about making something impenetrable, it's about making it more difficult. For example, modern encryption is very difficult for present-day computers to crack, but won't be that hard for quantum computers to crack.

Also, you're discounting the possibility of multiple layers of biometric + non-biometric authentication. Password/Private-Key + retina scan + left big toe-print scan >= Password/Private-Key.

I also think there are ways to authenticate your identity outside of static data-points if there's a trusted 3rd party real-time system involved.

Re: Finding vulnerable Twitter accounts with expired domains

#123
post #93
post #87

Earlier quoted context omitted.

If you set login to require 3/10 then 3 of those ways would need a security flaw before your account is compromised.

and then you'd need 3 factors just to log in, let alone any additional MFA those have

Yeah, I guess it could be inconvenient. On the other hand for many things I don't need to log in very often due to cookies keeping me logged in.

Re: Finding vulnerable Twitter accounts with expired domains

#124
post #29

Earlier quoted context omitted.

This is a solved problem in many other countries. Instead of proposing some new solution maybe it would be better to copy an existing which has already proven to work.

Without sharing examples, this is effectively a non-answer. Thanks for the comment.

I'm not here to babysit you. If you were serious about wanting to make a suggestion you would have started by looking at the current solutions. Not doing that is just a waste of screen estate.

Re: Finding vulnerable Twitter accounts with expired domains

#125
post #90
post #53

Earlier quoted context omitted.

> Without emails as the keys to the kingdom, what would you use? From Ursula K. LeGuin's indispensable "Dispossessed": “You're really much too polite for ...” “For what?” “For an anarchist,” she said, in her thin and affectedly drawling voice (it was the same intonation Pae used, and Oiie when he was at the University). “I'm disappointed. I thought you'd be dangerous and uncouth.” “I am.” She glanced up at him sidelo…

That seems vulnerable to the Spartacus attack.

The denizens of Anarres don't own any personal belongings, having abolished private property. A cheap trick to circumvent bad actors.

Re: Finding vulnerable Twitter accounts with expired domains

#126
post #125
post #90

Earlier quoted context omitted.

That seems vulnerable to the Spartacus attack.

The denizens of Anarres don't own any personal belongings, having abolished private property. A cheap trick to circumvent bad actors.

But a name must have some use, or why have one?

Non-physical things such as a reputation can be stolen or at least borrowed, too.

Re: Finding vulnerable Twitter accounts with expired domains

#127
This is how I used to get all kind of old ICQ numbers back in the 90s. Hotmail addresses, back then, used to expire.

Ironically enough, I've been vulnerable to the described attack afterwards as I had my own domain, didn't use it much anymore, and gave it away (to a band with the same nickname). Back then, a domain was pricey, and I was poor, so...

Re: Finding vulnerable Twitter accounts with expired domains

#128
post #106

Earlier quoted context omitted.

> Without emails as the keys to the kingdom, what would you use? PKI. Service providers shouldn't give you access to an account just because you can prove you control an email address (during a narrow and predictable time window, no less). The simplest thing would be to encrypt the relevant part of the payload (the one containing the password reset link), so resets are only possible if you can receive the email and h…

But Photo ID was forged long before the computers came along. There's always some way of getting around the security if you really want to. That is part of why we don't want to give in to electronic voting even though we work with computers.

This is not a retort. The claim is not that photo ID is unforgeable. The claim is that "it would ameliorate a lot if it meant that people had to show up in person somewhere".
Post reply on HN