Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

161–170 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#161

Earlier quoted context omitted.

Aztec is more compact than QR - does not need margin and because it's optimised for lowercase letters (used a lot for urls). Also has tunable error correction.

> because it's optimised for lowercase letters (used a lot for urls). Case does not matter for URLs, HTTP://NEWS.YCOMBINATOR.COM will work perfectly, and can be encoded using qrcode's alphanumeric mode. Aztec is slightly more efficient regardless, but not by much: qr alpha is 5.5 bits symbol, Aztec is 5 bits per symbol.

However, https://news.ycombinator.com/REPLY?id=15319423 does not work. Domain names are fine, because DNS is case insensitive in the ascii region by specification; I don't know about punycode for Unicode domain names. Paths beyond the domain name are expected to be case sensitive, but may be insensitive depending on the server environment (windows servers usually would be insensitive when serving files, Yahoo servers have a plugin to lowercase everything in the path to help with people typing in urls from offline media where users or publishers may not be very careful.

Re: Post a boarding pass on Facebook, get your account stolen

#162
post #141

Earlier quoted context omitted.

Or use a memorable phrase from literature. > This was not the last encounter between Bobby Shaftoe and Goto Dengo

Necronomicon quote? Nice. This has me thinking about what I can do to make my security answers to security questions untethered from PII. A book quote is a really good idea.

Close! Cryptonomicon.

I'm guessing that having every book loaded into a password cracking database, subdivided and indexed by each leading phrase word, is still computationally infeasible for non-government actors.

Re: Post a boarding pass on Facebook, get your account stolen

#163
It's not just posting photos that can cause this kind of trouble. I get a lot of email intended for other Doug Webbs sent to my gmail account, with variations on the presence/location of periods, or CC'd with another gmail account that's the same but with numbers on the end. For a while I was getting boarding passes from a major airline for a Doug that was frequently flying up and down the US west coast. Those emails gave me the confirmation number, and a link directly to the page that would let me make changes to the reservation, with no security barrier at all.

Granted, this most likely was caused by that other Doug providing my email address to the airline, but the airline is at fault too for assuming that access to a given email address is proof of identity. That's a very common mistake, often made intentionally to provide a more "user-friendly" experience. Had I been malicious, I could have caused that other Doug a lot of un-friendly grief.

I was not able to see any contact information on the reservation, and I didn't have full access to his account. (I don't know if a "Forgot Password" request would have given me that, though it probably would have.) I contacted the airline customer support to tell them they had the wrong email address on the reservation and they should contact their customer through some other means if they could. I think I got a form-letter thank you and never heard from them again, but I did get a few more boarding passes for a while.

I also get a lot of online shopping order/shipment confirmations, and plenty of personal correspondence. I try to tell the senders to fix their address books, and when I get a CC with the real address I contact the other Dougs too, but most of the time there's no response. I've had to set up a filter that puts all email with TO addresses that aren't the one I use into an "Other Dougs" folder, which I treat like spam.

Re: Post a boarding pass on Facebook, get your account stolen

#164
post #141

Earlier quoted context omitted.

Sounds like a "correct battery horse staple" would fit the bill

Or use a memorable phrase from literature. > This was not the last encounter between Bobby Shaftoe and Goto Dengo

I would definitely be weary of using the same answer in multiple places. Even more so than with passwords. These stupid answers clearly get stored unhashed (how else would they be verified via phone?). Do if the system gets compromised the attacker now has your security question response for multiple targets.

Other than being pronounceable I see the exact same requirements for security questions as for passwords. If anything they need to be stronger.

Re: Post a boarding pass on Facebook, get your account stolen

#165
post #143

Earlier quoted context omitted.

I know very few women that have done that TBH.

Maybe you just didn't realize it, because it isn't very common to see someone's full name? It was very much the norm until the 80s-90s, and even today I think the majority of women still go that route. I just spent a couple minutes searching Facebook to sanity check myself, and so far all of the women I'm friends with who are under 30 and married have done it.

Most if not ~all of those women are doing it so people can find them on Facebook, and people in the States rarely use the middle name field anyways except for legal docs.

Re: Post a boarding pass on Facebook, get your account stolen

#166
Recently saw a viral tweet with a picture of a political mailing posted on twitter with the address blacked out, but the USPS bar code (https://en.m.wikipedia.org/wiki/Intelligent_Mail_barcode) showing (looks like a comb with broken teeth).

They obviously didn't know the barcode contained the precise house address of the recipient (presumably the user's home address). Anonymization is hard!

Re: Post a boarding pass on Facebook, get your account stolen

#167
post #124
post #78

Earlier quoted context omitted.

The first time (years ago...) I had to enter my birth date on a website that asked it to me for no valid reason, there was a default value. It's now my birthdate on every others !

January 1st 1970 is sometimes known as "The Internet's birthday" for this reason..

It's also the "UNIX Birthday".

Re: Post a boarding pass on Facebook, get your account stolen

#168

Earlier quoted context omitted.

I don't even try to make it sound legitimate. e.g. How many sisters do you have? Anyone guessing will be trying a number between 0 and 5. I use a semi-random word, colour or car I associate with my sister(s), eg. Audi. When asked for a number no one guessing will respond with a car make.

Someone has the idea behind challenge/response. You don't have to answer the challenge with a 100% truthful, legitimate, accurate response, because the point is to NOT provide an answer that could be guessed by framing the response in truth, or even reality. So long as you've picked one that matches with what you've preseeded, use a random word/phrase as your response. q: What is the name of your favorite teacher? a:…

Yeah, but the key is you need to be able to remember it. Sure, you could store it somewhere, but often times the reason you are needing to use it is because you don't have access to your normal system (computer, phone) that you use to login with.

Re: Post a boarding pass on Facebook, get your account stolen

#169

It's not just posting photos that can cause this kind of trouble. I get a lot of email intended for other Doug Webbs sent to my gmail account, with variations on the presence/location of periods, or CC'd with another gmail account that's the same but with numbers on the end. For a while I was getting boarding passes from a major airline for a Doug that was frequently flying up and down the US west coast. Those emails…

Yup, I get emails about Cassidy's kids, Conrad's car purchase, Clyde's Lion's Club meetings, etc.

Re: Post a boarding pass on Facebook, get your account stolen

#170
post #121

Earlier quoted context omitted.

In the US and other countries it's common for a wife to take her husband's last name. Changes from "Jane Doe" to "Jane Smith"

Yeah, but often (usually?) the woman's maiden name replaces her middle name. E.g. Jane Elizabeth Doe -> Jane Doe Smith. I'm pretty sure my mom's maiden name is printed on her driver's license, paper checks, etc.

That is not super common in the US.
Post reply on HN