Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

151–160 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#151
post #141

Earlier quoted context omitted.

Sounds like a "correct battery horse staple" would fit the bill

Or use a memorable phrase from literature. > This was not the last encounter between Bobby Shaftoe and Goto Dengo

Necronomicon quote? Nice. This has me thinking about what I can do to make my security answers to security questions untethered from PII. A book quote is a really good idea.

Re: Post a boarding pass on Facebook, get your account stolen

#152
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

I ran into an issue with this a few times... What was the fake birthday I entered?!

Re: Post a boarding pass on Facebook, get your account stolen

#153
post #146

Earlier quoted context omitted.

How are they supposed to know you use one?

Not that they can really know, but most I've seen is that they disable pasting anything into the website, effectively making banking super slow for us with password managers and long passwords. Fortunately, my bank doesn't disable pasting (Banc Sabadell in Spain). Instead the password is restricted to maximum 6 numbers for login. Yay banks!

6 characters? Let me guess, were there restrictions on character space and case?

One place I had an account has a password input that restricts all of those, so it's like an 8-10 character string of all capital letters. I don't understand it at all.

Re: Post a boarding pass on Facebook, get your account stolen

#154
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

One trick is to use pronounceable passwords as answers to security questions, like a sequence of words (“Mother’s maiden name?” “correct horse battery staple”) or arbitrary syllables that make it sound as if you’re having a mini-stroke (“Where were you born?” “prisencolinensinainciusol, oll raigth”).

Re: Post a boarding pass on Facebook, get your account stolen

#155
post #143

Earlier quoted context omitted.

I know very few women that have done that TBH.

Maybe you just didn't realize it, because it isn't very common to see someone's full name? It was very much the norm until the 80s-90s, and even today I think the majority of women still go that route. I just spent a couple minutes searching Facebook to sanity check myself, and so far all of the women I'm friends with who are under 30 and married have done it.

In my experience, the women do that so people that knew their name pre-marriage can find them, not because that is their full name.

Re: Post a boarding pass on Facebook, get your account stolen

#156
post #93

Earlier quoted context omitted.

"Your mother's maiden name has numbers in it?" (bank teller, DMV person, etc.) "You .. give real answers for your security questions? Seriously?" I do the same thing, real birthday if it's financial or employee related, but for everything else, I'm a few years older on another date. I often pick a security question that I don't have a real legit answer to as well.

I never quite got this "mother's maiden name" thing. Isn't your mother's maiden name... your mother's current name, minus the extra surname she got when she married? Why is this treated as a hard-to-discover information?

"Mothers maiden name" has been used in over-the-counter banking as an authentication secret for over a century (1882 first mention[0])

Likewise DOB and SSN have been long established as auth secrets.

They never should have survived the transition to the internet

[0] http://splinternews.com/your-mothers-maiden-name-has-been-a-...

Re: Post a boarding pass on Facebook, get your account stolen

#157
post #134
post #60

Earlier quoted context omitted.

And if the scammer moves your fare to an earlier flight, they get away and your ticket is void when you show up.

Chances are they'll figure this out before the flight in question lands, and have someone to arrest the scammer at the destination.

Has this happened?

Re: Post a boarding pass on Facebook, get your account stolen

#158
post #143

Earlier quoted context omitted.

I know very few women that have done that TBH.

Maybe you just didn't realize it, because it isn't very common to see someone's full name? It was very much the norm until the 80s-90s, and even today I think the majority of women still go that route. I just spent a couple minutes searching Facebook to sanity check myself, and so far all of the women I'm friends with who are under 30 and married have done it.

I wouldn't use Facebook as a guide. My sisters all have done for facebook, but none of them have legally changed their middle name. They just do it on facebook so that people can find them.

Re: Post a boarding pass on Facebook, get your account stolen

#159
post #81

Earlier quoted context omitted.

Not just easier, but actually more safe. The person on the phone isn't usually aware about your security "paranoia" and is being evaluated on how much customers he/she has been able to help. As such most helpdesk employees will accept the answer "Oh I forgot, I do remember I put some random characters in there"... and your random password end up not helping you after all.

As noted in another comment, the attack on this of "oh I forgot, it's random characters" requires the attacker to know you do this. So if you do this, don't go disclosing it on public websites.

>requires the attacker to know you do this

Nah, "well, it kinda looks like random characters" is information a support rep will give you.

Welcome to social engineering and info escalation.

Re: Post a boarding pass on Facebook, get your account stolen

#160

Earlier quoted context omitted.

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

You don't have to say "oh I just mash the keyboard for those", you can say "it's weird, bear with me" and read it out from your password manager.

I do exactly this. About 4-5 characters in the support person interrupts me with "yeah, whatever".

The entire security question situation makes me incredibly pessimistic that we will ever get good security. The idea of security questions is so mind numbingly stupid to me yet it's widely used. One would have thought that after the Sarah Palin hack years ago everyone would have realised that but it seems like nobody did. The support agent didn't see my security question and go "oh that's clever". That's despite him being a person who deals with these all day they should realise the overwhelming stupidity. In a sane world companies who tell their users to use special characters etc. in their passwords and rotate them but then encourage them to mess it all up by storing information from their Facebook page ad a replacement for the password should have to pay massive fines. Yet hardly anybody is even seeing a problem with this.

This situation to me is so demotivating because it makes me think that whatever security mechanism we come up with well meaning people will undermine it.

Post reply on HN