Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

201–210 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#201

Recently saw a viral tweet with a picture of a political mailing posted on twitter with the address blacked out, but the USPS bar code ( https://en.m.wikipedia.org/wiki/Intelligent_Mail_barcode ) showing (looks like a comb with broken teeth). They obviously didn't know the barcode contained the precise house address of the recipient (presumably the user's home address). Anonymization is hard!

Like SSNs (with a defined purpose), IMbs "use" is to help the USPS sort and deliver the mail without manual handling.

Large mailers (billions of pieces per year) get a postage discount by applying such barcode to all the pieces. (edit: any mailer can get the discount. it just adds up for the larger mailers) Those pieces are delivered to USPS facilities, dumped into the auto-sorters and end up at the local post office with no human handling.

It should not be used for anything else except handling mail.

Re: Post a boarding pass on Facebook, get your account stolen

#202
post #105

Earlier quoted context omitted.

It's not about what you say, it's about what an attacker can get away with saying. And they can almost certainly get away with "I just mash the keyboard."

How would the attacker know that you mashed the keyboard when answering 'What high school did you go to?' ?

Most likely from a "helpful" CS agent offering up the hint above. "It's really weird" or "I've never seen that one before" or just an odd chuckle. Anything an attacker could use to gain an advantage will be used to compromise you eventually.

Re: Post a boarding pass on Facebook, get your account stolen

#203
post #198

Earlier quoted context omitted.

> The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account I used to do this and then lost my password file. Fast forward to a call with AT&T. I told them I forgot my secret answers. They offered that it was "a super weird answer," which let me use the "mashed…

correct horse battery staple?

This is a reference to the XKCD comic, Password Strength [1].

[1] https://xkcd.com/936/

Re: Post a boarding pass on Facebook, get your account stolen

#205
post #105

Earlier quoted context omitted.

It's not about what you say, it's about what an attacker can get away with saying. And they can almost certainly get away with "I just mash the keyboard."

How would the attacker know that you mashed the keyboard when answering 'What high school did you go to?' ?

How hard do you think it is to get a bored call center employee to give you enough of a hint to know that it’s random characters?

Re: Post a boarding pass on Facebook, get your account stolen

#206

Earlier quoted context omitted.

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

> The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account I used to do this and then lost my password file. Fast forward to a call with AT&T. I told them I forgot my secret answers. They offered that it was "a super weird answer," which let me use the "mashed…

Yea, I always use a handful of random words. That way, it's something pronouncable over the phone.

Still, I expect "oh, it's a random word not related to the question" would clear phone screen human layer of verification a good percentage of the time.

Re: Post a boarding pass on Facebook, get your account stolen

#207

Earlier quoted context omitted.

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

One solution would be to randomly generate security answers with human readable words. Diceware does this. You can use a dice, or you can use an open source tool like this one: https://www.rempe.us/diceware/#eff https://en.wikipedia.org/wiki/Diceware

It's also built into 1Password. And before that, I just used what I think was literally a one- or two-line Perl script that just grabbed four words from /var/dict. Why yes, my mother's maiden name was indeed pathetic xylophone tootsie wasp, how did you know?

Re: Post a boarding pass on Facebook, get your account stolen

#208
post #61

Just to clarify in case someone assumes the same thing I did from the headline: it isn't the Facebook account that gets stolen, but the airline website account.

And really this has nothing to do with Facebook at all, it's not a good title.

Eh, Instagram is owned by Facebook, so I gave that a pass.

Re: Post a boarding pass on Facebook, get your account stolen

#209

It's not just posting photos that can cause this kind of trouble. I get a lot of email intended for other Doug Webbs sent to my gmail account, with variations on the presence/location of periods, or CC'd with another gmail account that's the same but with numbers on the end. For a while I was getting boarding passes from a major airline for a Doug that was frequently flying up and down the US west coast. Those emails…

(my data point ...)

I get mail from a bank for someone who misspelled their email but their name is very close to mine.

I called the bank, reported that I was getting their email and they tried to sell me their identity theft service. ( Give us your SSN to check to see if you ... )

American Express didn't care that one of their subscribers personal information wasn't getting to their customer, but wanted to sell me service.

Re: Post a boarding pass on Facebook, get your account stolen

#210

It's not just posting photos that can cause this kind of trouble. I get a lot of email intended for other Doug Webbs sent to my gmail account, with variations on the presence/location of periods, or CC'd with another gmail account that's the same but with numbers on the end. For a while I was getting boarding passes from a major airline for a Doug that was frequently flying up and down the US west coast. Those emails…

Let's talk about common first and last name @ Gmail.... It is ridiculous. Oh the things I have seen. I have gotten multiple financial account resets over the years.... Retirement account statements with resets..... Loan info...
Post reply on HN