Live data from Hacker News

Stop Hacklore – An Open Letter

hacklore.org

21–30 of 115 posts

Re: Stop Hacklore – An Open Letter

#21
post #6

> Never scan QR codes: There is no evidence of widespread crime originating from QR-code scanning itself. > The true risk is social engineering scams... Exactly. My grandma is very susceptible to phishing and social engineering, I don't want her scanning random QR codes that would lead to almost identical service to the one she would think she is on and end up with identity theft or the likes. > Regularly change pass…

> Database leaks happen all the time

The point is to use unique passwords. If there is a leak, hopefully it is detected and then it is appropriate to change the password.

Re: Stop Hacklore – An Open Letter

#22
post #8

Note that most of the signers are from companies which collect substantial consumer information for revenue purposes. Hence the emphasis on "updating". And the absence of "turn up browser security levels to max" or "get a good ad blocker". Also, any password manager that's "cloud based" is potentially a security hole. Yeah, they say the server is secure. Right.

Password managers are one of those things I am still stunned is staying popular for advice, even though it's nearly akin to "use one password for everything". I assume a big part of it is the affiliate deals subscription password managers have with infosec influencers. There are absolutely valid use cases, but they are much fewer and further between than people claim.

It would be interesting to do a study (if one hasn't already been done) on whether password manager use reduces the number of compromises an individual has or not.

I think if used correctly they can be a net benefit, but the question is how many users actually use them correctly. Isn't the security they offer based on a user only having to remember a single complex and unique password for the manager, and then let it handle unique and complex passwords for everything else. The question is, however, how many users just set the password manager password to 'ImSecure123!' and use it to autofill the same old reused passwords they've always used?

Re: Stop Hacklore – An Open Letter

#23
post #16

I find it interesting that the comment about VPNs offering little additional privacy or security benefits is wrapped up under 'Avoid Public WiFi' rather than being called out explicitly. It drives me nuts all the ads I see for NordVPN or whatever claiming that by using their services you are now totally safe from all the hacks. If anything, it makes the median user less safe because they have a false sense of securit…

NordVPN is also one of the worst offenders in borderline marketing campaigns. Really questionable company.

Re: Stop Hacklore – An Open Letter

#24
I have two more to add to the list:

> Secret questions

No, my mother's maiden name is not a secret. And some questions like "who was your best friend in elementary school?" might have different answers depending on when you ask me. Plus, unless my best friend's name was Jose Pawel Mustafa Mungabi de la Svenson-Kurosawaskiwitz (we used to call him Joe) it's pretty easy to guess with a dictionary attack. The only way to answer these questions securely is to make up an answer that's impossible to guess, which results in a second password.

> You password must contain these particular characters

I understand that this rule is to prevent people from using passwords like "kittycat", but "k!ttyc4T" is still less secure than "horse battery staple correct".

Re: Stop Hacklore – An Open Letter

#25
post #6

> Never scan QR codes: There is no evidence of widespread crime originating from QR-code scanning itself. > The true risk is social engineering scams... Exactly. My grandma is very susceptible to phishing and social engineering, I don't want her scanning random QR codes that would lead to almost identical service to the one she would think she is on and end up with identity theft or the likes. > Regularly change pass…

Forced password changes are one of those security theater exercises that drive me absolutely nuts. It's a huge inconvenience long-term, and drives people to apply tricks (write it on a post-it note, or just keep adding dots, or +1 every time).

Plus, if your password gets stolen, there's a good chance most of the damage has already been done by the time you change the password based on a schedule, so any security benefit is only for preventing long-term access by account hijackers.

Re: Stop Hacklore – An Open Letter

#26
post #8

Note that most of the signers are from companies which collect substantial consumer information for revenue purposes. Hence the emphasis on "updating". And the absence of "turn up browser security levels to max" or "get a good ad blocker". Also, any password manager that's "cloud based" is potentially a security hole. Yeah, they say the server is secure. Right.

Password managers are one of those things I am still stunned is staying popular for advice, even though it's nearly akin to "use one password for everything". I assume a big part of it is the affiliate deals subscription password managers have with infosec influencers. There are absolutely valid use cases, but they are much fewer and further between than people claim.

It's completely the opposite of "use one password for everything". When you do that any single compromise of a website you have an account on means all your accounts are likely compromised. With a password manager you have a long random password for every single website, meaning a compromise is siloed to just that site.

Even if your password vault is stored on the cloud you're likely using a very secure passphrase for it that has 0 reuse anywhere else, so even if your password vault is stolen it's impossible to brute force.

For a hacker to comprise your password vault it would likely involve hacking your computer, which if you're keeping your software updated is a very difficult task these days without the target user's active help.

Re: Stop Hacklore – An Open Letter

#27
Don't worry about cookies or bother using a VPN, because... you are being tracked anyway? What's the point of including such a defeatist stance?

> the real world across industry, academia, and government.

Gotcha, so no one here gives a shit about privacy. They only care about avoiding the inconveniences of fraud and leaked secrets.

Use a password manager and a feature-complete adblocker (ublock origin on Firefox). Send messages over end-to-end encrypted channels. Use a VPN along with your adblocker and some kind of cookie/browser-id isolation if you don't want your traffic stalked.

Re: Stop Hacklore – An Open Letter

#28

This has the energy of "Remove all DEI initiatives because we have solved workplace discrimination." > This kind of advice is well-intentioned but misleading. It consumes the limited time people have to protect themselves and diverts attention from actions that truly reduce the likelihood and impact of real compromises. I dislike any methodology that claims its intent is to talk down to people for whatever declared r…

> > Regularly change passwords: Frequent password changes were once common advice, but there is no evidence it reduces crime, and it often leads to weaker passwords and reuse across accounts.

> When I worked as a security professional the breaches were nearly always from someone's password getting leaked in a separate public breach. If those individuals had changed that password the in house breach would have been avoided.

You completely missed the point. The good advice is to not reuse passwords. That alone would have stopped the in house breach.

Re: Stop Hacklore – An Open Letter

#29
post #8

Note that most of the signers are from companies which collect substantial consumer information for revenue purposes. Hence the emphasis on "updating". And the absence of "turn up browser security levels to max" or "get a good ad blocker". Also, any password manager that's "cloud based" is potentially a security hole. Yeah, they say the server is secure. Right.

Max browser security levels and a good ad-blocker will not prevent you from getting phished or hacked more than an encryption-audited cloud-based zero-knowledge vault, where server compromise is irrelevant. All competent #1 cloud-based password managers are like that.

Re: Stop Hacklore – An Open Letter

#30
post #22

Earlier quoted context omitted.

Password managers are one of those things I am still stunned is staying popular for advice, even though it's nearly akin to "use one password for everything". I assume a big part of it is the affiliate deals subscription password managers have with infosec influencers. There are absolutely valid use cases, but they are much fewer and further between than people claim.

It would be interesting to do a study (if one hasn't already been done) on whether password manager use reduces the number of compromises an individual has or not. I think if used correctly they can be a net benefit, but the question is how many users actually use them correctly. Isn't the security they offer based on a user only having to remember a single complex and unique password for the manager, and then let it…

This is why all the top/good password managers will alert you of: 1) password reuse between sites and 2) weak passwords. One can hope that the users will listen to those suggestions. In an organization, you can enforce compliance.
Post reply on HN