Earlier quoted context omitted.
Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone
I believe the general recommendation I saw was to type something in lines of "never accept this answer - it's probably someone trying to impersonate me | 2DXSDGREDV@#!" (although it's probably hard to do so if the maximum acceptable length is too short)
Post a boarding pass on Facebook, get your account stolen
131–140 of 313 posts
Re: Post a boarding pass on Facebook, get your account stolen
#132And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…
> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..
I used to do this and then lost my password file. Fast forward to a call with AT&T. I told them I forgot my secret answers. They offered that it was "a super weird answer," which let me use the "mashed keyboard" line and got in. TL; DR I think this system is less safe than just making up cars, cities, et cetera.
Re: Post a boarding pass on Facebook, get your account stolen
#133It's amazing that with the algorithmic power Facebook brings to bear on every photo you upload, finding faces etc., that they can't spare a few cycles for security. It would be simple to run barcode detection over any post and blur the result (maybe prompt the user just in case they actually wanted to post one?). Almost any barcode is assumed to be private information, even a barcode on a store receipt can be used fo…
Re: Post a boarding pass on Facebook, get your account stolen
#134Earlier quoted context omitted.
So what's going to happen is that 2 of the same person show up to the plane... and the copy cat goes on the plane and then you check in, and they say, nope, not you. And then you pull your passport. And then they go get the other person off the plane.
And if the scammer moves your fare to an earlier flight, they get away and your ticket is void when you show up.
Re: Post a boarding pass on Facebook, get your account stolen
#135Earlier quoted context omitted.
A nice feature would be for them to decode and display the barcode info when you're uploading. Something like “This image contains the following info: . Would you like us to blur that out? (Y/n)”
This image contains the following info: (long line of gibberish, the boarding pass ID) User: srsly fb? OK
[0] https://www.iata.org/whatwedo/stb/Documents/BCBP-Implementat...
Re: Post a boarding pass on Facebook, get your account stolen
#136And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…
My bank's terms of service bans recording passwords - ie managers.
Re: Post a boarding pass on Facebook, get your account stolen
#137Earlier quoted context omitted.
It's not about what you say, it's about what an attacker can get away with saying. And they can almost certainly get away with "I just mash the keyboard."
Ah, I see what you mean. Perhaps instead of grabbing a handful of characters from /dev/urandom, you generate a passphrase (a few random dictionary words)?
Re: Post a boarding pass on Facebook, get your account stolen
#138Earlier quoted context omitted.
Not just easier, but actually more safe. The person on the phone isn't usually aware about your security "paranoia" and is being evaluated on how much customers he/she has been able to help. As such most helpdesk employees will accept the answer "Oh I forgot, I do remember I put some random characters in there"... and your random password end up not helping you after all.
As noted in another comment, the attack on this of "oh I forgot, it's random characters" requires the attacker to know you do this. So if you do this, don't go disclosing it on public websites.
The random character thing isn't great for this use, it seems, as a result.
Re: Post a boarding pass on Facebook, get your account stolen
#139Re: Post a boarding pass on Facebook, get your account stolen
#140Not the first time airlines have had poor security with boarding passes: https://medium.com/@da/need-a-last-minute-flight-45af88ec8df... https://www.wired.com/2016/08/fake-boarding-pass-app-gets-ha... https://puckinflight.wordpress.com/2012/10/19/security-flaws... http://www.washingtonpost.com/national/experts-warn-about-se... And what the OP article is basically copying: https://www.theverge.com/2017/1/10/14226034/i…